The quickstart now includes a planning time allowance, explains the automatic folder-access rules separately from AI sign-in, and summarizes what to have ready for Telegram, Slack, and WhatsApp.
The quickstart groups setup choices into labeled terminal illustrations based on the setup code. Consistent checkpoints and compact sign-in references help readers follow each action through to its result. The terminal illustrations are synthetic, not installation screenshots.
Added a pull-request check for dated Docs updates entries, with explicit exceptions for typos, formatting, and verification-only changes. Contributor and automated-workflow instructions now reserve release notes for product changes and describe documentation changes in this log.
Added an internal page inventory, reader-journey audit, prioritized editing backlog, and visual capture plan. A documentation validation workflow is prepared for pull requests; installation tests, reader sessions, and remaining accessibility review are tracked separately.
Corrected current behavior against upstream
main at b76fcb3d, with channel payload checks at 6d5c1d08 and provider payload checks at f503f23c. Narrow corrections retain older verification stamps for untouched claims.- Setup and operations: existing-install template choices, model fallback and fast mode, Docker inspection commands, image checks, credential admission, and scheduled-task cleanup now match the implementation.
- Session boundaries and recovery: the guides distinguish separate provider conversations from confidentiality. Agents can retrieve another session’s history within their own group. Lifecycle guidance describes driver-backed startup, adoption, durable claims, and event-driven reconciliation.
- Channels: Teams follows the CLI provisioning flow; Slack describes managed installation, mention-triggered shared rooms, and the limits of membership events. WhatsApp Cloud uses its actual webhook path.
- References and extensions: link-only cards, richer conversation metadata, default-instance DM caching, plugin-owned MCP servers, and skill refresh are aligned with source. Reserved wake-signal storage is clearly distinguished from active runtime coordination.
- Release scope: new main-branch behavior is listed under Unreleased, without inventing a numbered release.
The introduction now starts with an everyday example and explains what running an assistant involves. The template getting-started guide adds clear prerequisites, connection checks, and task-specific next steps.
- Explained the separate template-creation and conversation-connection steps, including a source-verified terminal path.
- Scoped routine inspection and activation to the chosen assistant, and corrected the existing-install and first-message guidance.
- Added a labeled conversation illustration, template-selection cards, and a real sign-in completion screenshot with provenance.
The quickstart now walks through opening Terminal, checking Git, installing NanoClaw, and getting a first reply before connecting a messaging app. Each milestone explains what you should see next.
- Replaced the compressed wizard inventory with a guided path and optional alternatives.
- Added NanoClaw sign-in screenshots with action captions and a clearly labeled example conversation.
- Distinguished the NanoClaw download account from the AI account, and made the terminal-agent creation choice explicit.
- Moved technical installation details to the existing reference and added help for common setup interruptions.
The first half of the drift sweep opened on 2026-08-28 (nanoclaw-docs#373). Each page below was re-verified only where it changed, against
nanocoai/nanoclaw@294ef2ae and channels@4a263658, so several pages now carry a segmented verified-against comment rather than one bumped SHA.- The changelog covers v2.3.0. The entry was reconstructed from the merge window between the two version bumps. It was checked against code rather than against the upstream CHANGELOG. It names five breaking changes: the container driver seam, the asynchronous central database, the agent mailbox seam, the Node 22 floor, and the Slack agents decision gate.
- Mattermost gets its own page. Mattermost covers server discovery, the bot account, authenticated card callbacks, and the optional local evaluation server the skill can create.
/add-mattermostcopies a vendored adapter from thechannelsbranch instead of installing an npm package, which is unusual for a Chat SDK channel. The channels overview gains the row, the card, and the note that Mattermost takes chat over its own outbound WebSocket while card clicks come back on/webhook/mattermost. - Architecture names the driver seam. Each session is composed as a validated spec and realized by a driver. Containers now carry key-derived
ncl-names, and the old readable name survives as thenanoclaw-container-namelabel. The page also corrects the delivery model: for a provider that streams mid-turn text, closed<message>blocks are the only content door on a chat turn, and the final result no longer delivers content. It also dropsclaude-md-compose, which no longer exists, becausesrc/project-doc-compose.tsnow writes one flat project document with no@-imports. - Adapter interface catches up with the hook series. The page adds the status-bearing
setTyping,setThreadTitle,setSuggestedPrompts, and thedefaultsmember. It also documents the hooks a channel module registers: membership, bridge inbound policy, session created, post delivery, tool extension, and wizard companions. - Telegram matches what setup does now. The pairing code is 6 digits.
/connect_groupruns an owner-approval flow. The wizard offers a second bot throughTELEGRAM_BOT_TOKEN_<NAME>andTELEGRAM_INSTANCES. The legacy Markdown sanitizer is gone because the adapter renders CommonMark to MarkdownV2 itself.
Dial landed on trunk (nanoclaw#3050, adapter on the
channels branch via nanoclaw#3041) — verified against nanocoai/nanoclaw@475ba766 and channels@a45fab71.- New channels/dial — the native
dial-CLI adapter, the setup-wizard flow (CLI install andDIAL_CLI_PATH, email one-time-code sign-in, owner-only vs public line, restart and line registration, 6-digit SMS pairing with QR, the 10DLC note, the optional tool install), the shared-line model (number = messaging group, each correspondent a thread), delivery verdicts and the[NanoClaw system notice: …]failure path, voice-call and transcript routing, the pairing brute-force guard and itsDIAL_PAIRING_*knobs,/add-dial-number, and/add-dial-toolwith its per-agent OneCLI block rules. - Channels overview — Dial row (setup wizard: yes) and card; native-adapter and no-public-URL lists. Quick start and Installation — Dial in the wizard’s channel step,
pair-dialin the setup steps list. - Skills catalog — rows for
/add-dial,/add-dial-number,/add-dial-tool, plus the rest of the trunk drift since the last stamp:/add-anydocand/migrate-slack-agentsadded,/use-native-credential-proxyremoved (retired upstream). Count 45 → 49. Tools — a Dial section next to Tavily and the local-model tools.
Re-verified the public docs against
nanocoai/nanoclaw@dce271c6 and corrected the user-facing drift introduced after the v2.2.0 release.- Node 22 is now the minimum — installation no longer says Node 20 satisfies the host requirement. The package engine and bootstrap both require 22 or newer, and setup upgrades an older install.
- Unknown-sender policy coverage is complete — hardening, security, the entity model, adapter interface, both
nclpages, troubleshooting, and the database schema now includedecline_notify: a polite unknown-DM decline plus an owner/admin FYI, deduplicated for 24 hours. Group chats still drop silently. - Cross-session catch-up is documented —
ncl sessions historymerges inbound and outbound rows for another session in the same agent group, with scoped access, bounded human output, and full JSON output. - Conversation lifecycle schema caught up — messaging groups now document
detached_at, which preserves wiring and history while blocking delivery after the bot leaves, and pending approvals document the adapterinstanceused for later card edits. The CLI reference also fixes messaging-group identity to the full(channel_type, platform_id, instance)triple. - Adapter defaults include
sessionMode— channel authors can declare a thread-rooted context asper-thread; wiring creation stamps both the session mode and thread honoring together.
Rebuilt Slack around the managed-app flow and the multi-agent experience. The guide separates the base single-bot channel from the agents feature, explains per-agent Slack identities, shared agent rooms, canvases, per-thread sessions, the agent-to-agent safety boundary, and every Slack-specific environment variable in one place. The channels overview and skills catalog now point to the same model.The page follows the upstream payload split.
/add-slack installs the base channel: adapter, shared lib, bot-inbound guard, provisioning core, and the slack-formatting container skill. Rooms, canvases, direct-message onboarding, the extended create_agent, and the create_room and add_to_room actions install with /slack-a2a-rooms and /slack-agent-flow.This revision also corrects what setup actually asks and what it actually needs. Setup offers “Create it for me” by default and falls back to the manual walkthrough when sign-in, the Slack API, or the managed service fails. Managed setup needs only a NanoClaw account sign-in; SLACK_MANAGER_TOKEN is an advanced operator-supplied alternative, not a requirement. A workspace running Slack’s Admin Approved Apps policy needs an admin to approve the app before the bot token can be pasted. The “Create agents from Slack” section now follows the implemented step order. Setup applies the two Slack agent feature skills by default. Manual apps need the additional room and membership events as well as the additional scopes. Verified against trunk 001dfa02 and channels 9740352a.The diagram redraw below already corrected several claims in pictures; this sweep brings the surrounding prose in line. Every corrected claim was re-verified against
nanocoai/nanoclaw@249cf983:- Architecture — “one writer per file” now names its two deliberate host-side exceptions: command-gate denials written straight to
outbound.dband clearing a killed container’s orphaned processing claims, both under the same DELETE journal andbusy_timeoutdiscipline. The intro also stops saying the agent “never talks to the network”: it never touches the messaging platforms; its own egress is open by default and lockable. - Security model — “the blast radius is one session” corrected to one agent group: sessions share the group workspace read-write, so a compromise reaches the group’s files and
memory/tree, matching what the redrawn diagram already said. Conversation histories stay per-session. - Isolation levels — the four levels are now ranked correctly,
per-threadaboveshared, matching the page’s own decision tree and the code. - Container lifecycle and installation — the image sections lead with the actual default: setup pulls the pinned hardened image, and building locally from
container/Dockerfileis the explicit alternative. - First agent — idle containers are killed by the host sweep; the runner has no idle self-exit.
- Submitting a template — registry pins bumped: nanoclaw-templates#20 merged 2026-08-14 as
2e0dcd01, so the CONTRIBUTING pin now points at templatesmain.
All ten diagrams across the docs are now hand-drawn editorial SVGs (light and dark variants, drawn with the open-source diagram-design skill in the brand palette) instead of rendered Mermaid blocks. Each was also rethought around its page’s point rather than restyled 1:1:
- Architecture — the seven-lifeline sequence chart became a boundary-first view: host process above, container below, the two SQLite files sitting on the Docker mount boundary as the only crossings, and the end-to-end message story riding as numbered steps.
- Container lifecycle — the state machine now sits above the persistent mounted session state it orbits, so the disposability thesis is visible: everything above the line dies, everything below survives.
- Entity model — the wiring is drawn as the join at the center, carrying its five behavior axes; the access chain sits beside it.
- Isolation levels — the decision tree lands on a most-to-least-isolated spectrum, with the shared-filesystem caveat bracketing the three session modes.
- Security model — containment instead of a pipeline: the assume-injected agent inside the container boundary, host-side gates inbound, bounded filesystem, network, and approval paths out.
- Channels overview (trunk infrastructure versus the channels-branch catalog), first agent, multi-agent swarm (directed destination edges, including the host rejecting a send with no row), installation, and migrate from v1 (two-actor swimlanes around
handoff.json) follow the same treatment.
nanocoai/nanoclaw@48347e1, and several claims the old Mermaid carried were corrected in the process: the lifecycle now names the host sweep’s 30-minute idle ceiling instead of a runner self-exit that doesn’t exist, the isolation spectrum orders per-thread above shared, and the entity model names the real agent_group_members table. The Mermaid source for each diagram is kept in an MDX comment beside the embed for regeneration; the workflow is documented in the repo’s CLAUDE.md.Templates get their own documentation section, written against the Agent Plugins 1.0.0 format (nanoclaw#3220, nanoclaw#2909, nanoclaw-templates#19). Templates shipped in v2.1.24 but had no coverage beyond one line in the
ncl reference.- New “Templates” nav group — getting started with a template (a standalone newcomer path from a fresh machine, built to be linked directly from social), overview (what a template is, why the format is a vendor-neutral standard, the catalog), using a template (the wizard’s library picker and the
nclpath, ref resolution, post-stamp wiring and task activation), updating a stamped agent (the restamp dry run, what resets versus what is never touched, CUSTOMIZED flags), building (manifest,mcp.json, skills, persona, context extras, tasks, local testing, and the pre-plugin migration), and submitting (categories, registry standards, paid-service disclosure,check-templates.mjs, and the PR checklist). - New template format reference — field-level validation for
plugin.jsonandmcp.json, failure boundaries, the secret lint, size and containment caps, and thePLUGIN_ROOT/PLUGIN_DATAruntime contract. - Breaking format change documented —
plugin.jsonreplacescontext/instructions.mdas the discovery marker,.mcp.jsonbecomesmcp.jsonwith a declared transport per server, andcontext//tasks/move underai.nanoco.nanoclaw/. The persona is now optional to the loader. Conversion steps are in building a template. - Cross-links — the quickstart wizard list gains the first-agent template step,
nclCLI and the CLI reference document the restamp flags (--yes,--new,--id) and the plugin-owned MCP server guard, environment variables addsNANOCLAW_TEMPLATES_DIRandNANOCLAW_TEMPLATE_PATH, and first agent and scheduled tasks point at templates where readers will look for them. - Registry standards — the submission page carries the rules a contribution is held to, including the paid-service disclosure rule (a template may depend on paid MCP servers or API tiers, but its README must say so up front, link the tool, name the tier the template needs, and state that the user brings their own key — tiers rather than prices, which go stale) and the ban on affiliate links, baked-in billing, and author monetization. The matching text landed upstream in nanoclaw-templates#20, which also records that
check-templates.mjsfails on a credential-shaped key where NanoClaw’s stamp-time lint only warns, and corrects a checklist line that called the persona a registry requirement — it is optional, and a template without one uses NanoClaw’s default project doc.
main at 20d61af — nanoclaw#3220 and #2909 both merged 2026-08-13 — plus nanocoai/nanoclaw-templates@601071b (templates#19) and templates#20 for the registry standards, merged 2026-08-14 as 2e0dcd01. The plugin format ships in v2.2.0 (2026-08-13).Documenting the feature surfaced four upstream fixes now on #3220: template-stamped groups get the ag- id prefix every other creation path already had (nanoclaw#3234), --folder combined with --template is rejected rather than silently ignored, the stamp-time secret lint strips Bearer/Token/Basic prefixes before matching, and the upstream persona claim was corrected to match the code.Drift sweep against upstream trunk
639577c3 (38 commits past the previous sweep’s anchor 4446b5bd; still v2.1.54, no new release) and the providers branch 9cfea509. Channels branch unchanged.- Remote Streamable HTTP MCP servers (nanoclaw#3092, #3221) — tools, container config, MCP tools, self-modification, and both
nclpages now document the--urlform:add_mcp_servertakes anameand exactly one ofcommandorurl, HTTPS enforced, credential-bearing URLs rejected. - Gmail and Google Calendar tool skills removed upstream (nanoclaw#3172), Tavily added (nanoclaw#3190) — tools rewritten around
/add-tavily-tool(keyless remote MCP), the skills catalog drops four rows and adds one (45 skills), credentials reframes its stub-pattern example, extend overview swaps its tool-install exemplar. - iMessage Photon opt-in is now one text (nanoclaw#3181) — the wizard registers your number itself; the dashboard invite flow is gone from channels/imessage.
- OpenCode provider catch-up merged (nanoclaw#3122) — providers documents the three
OPENCODE_MODEL_*passthrough vars. nclCLI reference corrections — dashed positional ids resolve (the no-dashes rule was stale), group scope includestasksplus current-chatwirings get/update(nanoclaw#3137),groups createis idempotent with--template/--timezone,messaging-groups senddocumented, tasks flags completed with the 4-fires/day recurrence cap.- Approval cards keep their content at terminal states (nanoclaw#3143) — db-schema gains the
questioncolumn (migration 021) and the missedcontainer_configs.timezone(020); credentials updates the expiry wording. - Architecture — host-module lifecycle registry startup step (nanoclaw#3214) and the warm-stream trigger guard; first agent — group creation initializes the filesystem inline (the lazy-init story was stale); multi-agent swarm —
ncl wirings createdoes auto-create the channel destination; scheduled tasks — script failures back off and auto-pause after 8,wakeAgent: falseis a quiet success; writing skills — the guidelines’ three principles (nanoclaw#3211); upgrading —[BREAKING]migration guides now execute, not “by hand”.
639577c3 (providers pages to 9cfea509).Drift sweep for the v2.1.54 release (upstream
4446b5bd, channels c6cdc212).channels/imessage— rewritten for the unified channel (nanoclaw#3164): local (chat.db+ Full Disk Access) and hosted (nativespectrum-tsline via photon.codes) backends, the Photon device-login wizard with its manual dashboard opt-in, the first-text requirement, hosted media handling, the deterministic backend-resolution ladder, and a fullPHOTON_*configuration table. The removed remote mode,IMESSAGE_LOCAL/IMESSAGE_SERVER_URL/IMESSAGE_API_KEY, andimessage-cloudare flagged as a breaking change. Channels overview and the skills catalog rows now match.- Vercel CLI is opt-in — installation, container lifecycle, and the skills catalog no longer list
vercelamong the image’s baked-in CLIs; thevercel-clicontainer skill moved out of the base image and ships with/add-vercel. - Hardened-image fetch time — the quickstart and the Echo hardened runtime guide no longer say the fetch takes around 20 minutes; it’s now a few minutes, matching the installer’s wording.
reference/environment-variables— the failure-assist row notes that a non-Claude install dispatches assist to its picked provider first (nanoclaw#3170).
4446b5bd; channel anchors at c6cdc212.Second pass from the same-day drift sweep — pages that weren’t wrong but didn’t yet mention the hardened image where readers would look for it. Hardening gained the provenance-label scheme (
dev.nanoclaw.image-source: local / hardened / derived, plus the agent-runner lock label) and the two new default-blocked mount patterns. Credentials documents the registry sign-in as its own credential class: device-code flow, ~/.config/nanoclaw/account.json, and the docker credential helper that mints a short-lived password per pull. Configuration and the guide-adjacent pages picked up the three image-source variables, Installation the registry / registry-reconcile steps and the pull path, Container lifecycle the pull-and-retag alternative, and Providers the pinned-install nuance (Codex overlays onto the pulled image; OpenCode’s lockfile change drops the install to a local build). Container configuration also gained the timezone field from the earlier per-group-timezone feature. Every addition verified against nanocoai/nanoclaw@4e83a0a0; all nine stamps bumped.Same-day sweep after the hardened-image feature merged upstream (nanoclaw#3150): every page’s
verified-against files were diffed against the merge (4e83a0a0), 30 flagged pages adjudicated, four fixed.quickstart— the wizard’s sandbox step now describes both image paths: the recommended pre-built Echo image (sign-in, then a download that currently takes around 20 minutes) and the 3–10 minute local build. The walkthrough gained the sign-in step it was missing.operate/upgrading— image refresh guidance now branches by install:./container/build.shon local builds,pullon pinned installs (the bare form exits3there), and the refresh trigger includes theagent-imagepin moving inversions.json.guides/scheduled-tasks— task times follow the owning group’s timezone override (ncl groups config update --timezone, applies immediately) before the install default; the restart-required note now applies only to the default.reference/environment-variables— the six new registry and hardened-image variables documented, and seven stalesetup/auto.ts/setup/container.tsline citations recomputed (the file grew 253 lines under the feature).
Added
guides/echo-hardened-runtime: the Echo partnership’s opt-in hardened runtime for agent sandboxes — what it is, the minimal component set it ships, how to enable it during a new install, and what stays the same if you keep the DIY local runtime. Sits in the Operate group next to Hardening.The container pages described a posture that no longer matches trunk. Agent spawns now carry a fixed hardening set that no group or install can override (nanoclaw#2748):
--init, so docker-init is PID 1 and SIGTERM actually reaches the runner instead of being discarded — concepts/container-lifecycle had the inverse story, Bun as PID 1 with no --init — plus --cap-drop=ALL, --security-opt no-new-privileges, --shm-size=1g, and a --pids-limit fork-bomb backstop defaulting to 2048. That default lands as a new CONTAINER_PIDS_LIMIT variable on reference/environment-variables and a new always-on section on operate/hardening, alongside restamped src/config.ts line citations.Separately, channels/whatsapp said dedicated-number groups engage only on an explicit @-mention of the bot’s number. A typed @<agent name> or @<bot number> also triggers, as long as the message doesn’t mention-pill anyone else (nanoclaw#3087). Verified against trunk f1e66179 and channels 6ee516ad.Added
concepts/agent-memory, the first single-page explanation of NanoClaw’s provider-neutral memory system: the host and container paths, boot scaffold, Core Memory, session-start injection rules, 16,000-character per-file budget, OKF concept format, group sharing boundary, operator workflow, prompt-injection risk, and legacy migration. The page is verified against nanocoai/nanoclaw@f1e66179 and linked from the entity model, isolation, security, customization, providers, self-modification, installation, and quickstart pages.The site’s first screenshot: the quickstart’s “Answer the wizard” step now opens with a real capture of
bash nanoclaw.sh — the NanoClaw splash, Standard setup selected, the system check passed, and the sandbox build starting. Captured from an actual run of upstream main (d23db4f3) with VHS, so it can be re-rendered when the wizard’s look changes; nothing sensitive is on screen (the run ends before any credential step).First visuals in the Get started section, from a rich-content survey of those four pages:
migrate-from-v1— a flow diagram ahead of the step-by-step walkthrough, showing the migration’s two-actor shape:migrate-v2.shdoes the deterministic phases,handoff.jsoncarries the state, and the/migrate-from-v1skill finishes the judgment calls before the health checkinstallation— a small diagram of the three-stage installer chain (nanoclaw.sh→setup.sh→setup:auto) under “What the installer does under the hood”
e926e30e; no claims changed, so verified-against stamps stay put. More from the survey (hero chat screenshot on the introduction, a wizard terminal capture on the quickstart) lands separately.Micro-sweep of the delta since v2.1.53: trunk
e926e30e → d23db4f3 (11 commits, no release), channels branch 9e14cd0c → 7f24dd31 (one merge).channels/signal— the managed daemon now starts with--send-read-receipts(nanoclaw#3062), so senders see messages marked read once the daemon receives them. New Platform notes bullet, including the caveat that an externally run daemon needs the flag added manually. Channels-branch stamp bumped to7f24dd31here and onchannels/overview(whole-dir citation; overview’s claims are unaffected). The other channel pages cite files that are byte-identical across the two SHAs, so their stamps stay put per the drift-detection rulereference/environment-variables— 25 of the 35file:linecitations pointed at the wrong lines, and were already wrong at thee926e30estamp (asrc/config.tsrestructure predates the sweep; the sweep verified names and defaults but not line numbers). Every citation is now script-verified against source: the cited line must actually mention the variable. Trunk stamp stays ate926e30e— the cited files are identical atd23db4f3apart from aclaude.tschange well below the cited region- Checked, no docs impact: compaction no longer surfaces as a synthetic “Context compacted.” result — it logs as activity instead (nanoclaw#3083); no page ever claimed it appeared in chat. Upstream’s CHANGELOG dedup (nanoclaw#3063) touched unreleased entries the portal doesn’t mirror, and nanoclaw#3084 is test-only
The skills pages said a NanoClaw skill is a workflow “that Claude Code executes in your checkout”. Any agents-convention coding harness runs them, and upstream built that on purpose: nanoclaw#2810 added
.agents/skills → ../.claude/skills and AGENTS.md → CLAUDE.md so “an agents-convention harness (e.g. Codex) read the same skills and instructions as the .claude setup”. Both symlinks still resolve at e926e30e, and all three harnesses really do find our skills — Claude Code via .claude/skills, Codex via .agents/skills, OpenCode via all of .opencode/skills, .claude/skills and .agents/skills. Fixed in #355:extend/overview+reference/skills-catalog— “a coding harness (Claude Code, Codex, OpenCode)”, not “Claude Code”. “Harness”, not “agent”, deliberately: NanoClaw already calls the container instance an agent, so reusing the word for the host-side tool meant one term for two layers on the same page (extend/overviewdescribes both). Trunk makes the same split where both appear in one breath —.claude/skills/migrate-memory/SKILL.md:9reads “The coding harness running this skill - Claude Code, Codex, or another harness - owns the whole migration”, then hands off to “the NanoClaw group”- A syntax note on both pages —
/nameis Claude Code’s; Codex invokes the same skill as$add-telegramand does not accept/add-telegram(openai/codex#11817, closed “This is by design”); OpenCode has no typed form and loads skills through its ownskilltool. Three invocation models, not two syntaxes. The pages listed 48/nameliterals with nothing saying whose syntax that is, so a Codex reader following the catalog hit a rejection with no signpost. The note also says the skill file is the same one in every case, while flagging that a few skills still phrase steps in Claude Code’s tool vocabulary - Removed a false claim — the opening sentence said the coding agent reads and performs the skill “or the setup wizard dispatches an
/add-<channel>skill for you”. The wizard does not hand the SKILL.md to a harness; it applies the document itself through the directive engine (setup/lib/skill-driver.tsrunsapplySkillfromscripts/skill-apply.tsagainst thenc:fences, every non-test caller undersetup/). Two readers, one document — upstream’s own framing atdocs/skills-model.md:39 - Not fixed here: the invocation syntax the trunk docs themselves use. No literal form is correct on all three harnesses, so trunk needs a convention — filed upstream as nanoclaw#3072. This pass only describes what each harness does today
- Scope note: this is an agents-convention mirror, not end-to-end harness neutrality. Setup remains Claude-Code-shaped (
setup/lib/claude-assist.ts,claude-handoff.ts,install-claude.sh), and 13 of the 48 host skills name Claude Code tools in their steps - Method note: the first revision of this PR deleted “as slash commands in Claude Code” while leaving every
/nameliteral in place, which made the pages worse for exactly the reader they were meant to help. Three independent adversarial reviewers caught that, plus a stray “walks Claude through a task” the completeness grep had missed.verified-againstSHAs left ate926e30e: narrow prose fix, not a re-verification
Brought the whole site current with
nanocoai/nanoclaw@e926e30e (v2.1.53) — a ~15-release, ~230-commit delta since the v2.1.38 sweep. Every anchored page was re-verified claim-by-claim against source; 43 pages changed across eight PRs (#346–#354). The big upstream themes and what they touched:- The memory rework —
CLAUDE.local.mdis retired. Per-group memory is now thememory/tree (scaffolded at boot, shared by every provider, carried across provider switches) plusinstructions.prepend.mdfor standing instructions;usesMemoryScaffoldis gone from the provider interface. Rewritten acrossconcepts/*,guides/*,extend/providers,extend/self-modification,installation, andmigrate-from-v1(which now documents the staged-CLAUDE.local.md→/migrate-memoryflow) - Scheduled tasks moved to
ncl tasks— the six scheduling MCP tools are gone;guides/scheduled-tasksgot a ground-up rewrite,reference/mcp-toolslost its Scheduling section, andreference/ncl-cli+operate/ncl-cligained thetasksresource (including this sweep’s correction: all task verbs areopen, not approval-gated) - SKILL.md-driven setup — the wizard now dispatches
/add-<channel>skills; install prose corrected on the channels pages,extend/overview, andextend/writing-skills(which was still quoting a pre-flight block deleted in thenc:directive-fence rewrite) - Per-wiring
threadsaxis (migration 019) onconcepts/entity-model,reference/db-schema, the ncl pages, andchannels/discord - Token badge ~204k → ~226k (now frozen —
update-tokens.ymlwas deleted); container skills 8 → 6;DEFAULT_AGENT_PROVIDER; structured approval cards; host-onlyadd-mount/remove-mount - Method note: every area’s pre-verified “no content change, bump only” verdicts were re-checked adversarially before shipping — that re-check found real drift in all four areas it flagged, so it’s now a standing step of the sweep process
Follow-up sweep after the v2.1.38 pass. Trunk moved only three commits since
08a1ac9 (all in-repo docs — no source changes), and the channels branch is unchanged at 90dd87d, so the site’s claims against trunk and channels still hold. The providers registry branch did move (c570766 → d2dd91b, codex payload), and two leftover v2.1.4 stamps from the original reference pages were cleared:extend/providers— the codex provider’sAGENTS.mdcompose now opens with the group’s template persona (instructions.prepend.md, exempt from the 32 KB-cap eviction), template skills are mirrored into.agents/skillsas real directories (they’re stamped on the Claude plane, which Codex never reads), and the.agentsdir is mounted at both/workspace/agent/.agentsand/home/node/.agents— Codex only scans workspace-level.agents/skillsinside a git repo, so the$HOMEmount is what makes skills discoverable. Providers-branch anchor bumped tod2dd91breference/environment-variables— all 37 source citations re-checked atb6cb53e: every variable and default still accurate; 10 drifted line numbers corrected and the “line numbers reference v2.1.4” disclaimer updated to v2.1.38reference/container-config— the two “as of v2.1.4” absence claims (noncl groups configsubcommand forskills;add-mcp-server/add_mcp_serverdon’t acceptinstructions) re-verified still true at v2.1.38 and restamped; anchor bumped to08a1ac9concepts/contributing—pnpm run devnever had hot reload (tsx src/index.ts, no watch, unchanged since the initial commit); corrected the command comment. Surfaced by cross-checking the in-repo docs overhaul (nanoclaw #2961–#2964) against the portal- OneCLI accuracy pass (operator-audited, all 26 OneCLI-mentioning pages):
operate/troubleshooting’s “gateway not applied” hint told operators to check127.0.0.1:10254, but the host dials whateverONECLI_URLsays — on installs where containers reach the gateway, that’s the Docker-bridge IP and nothing listens on localhost;reference/environment-variableslistedhttps://api.onecli.shas the default forNANOCLAW_ONECLI_API_HOST, but unset means “install a local vault” (setup/auto.ts:238) — the URL is only the advanced-settings form placeholder;operate/credentialsnow notes that OneCLI’s own docs reserve “gateway” for the separate egress-proxy listener, while these pages use it loosely for the whole vault - New: “Accessing the OneCLI dashboard” (
operate/credentials) — the tool pages referenced connecting OAuth services “in the OneCLI web UI” without ever saying where that lives. The new section anchors it toONECLI_URL, covers the two headless-install gotchas (Docker-bridge bind not routable from your browser; OAuth Connect redirects need OneCLI’sAPP_URLset to the URL you browse from), and links out to the OneCLI docs;extend/toolsnow links the section
Brought the site current with
nanocoai/nanoclaw@08a1ac9 (v2.1.38) — a ~15-release delta since the v2.1.23 sweep. A code-grounded pass over the whole site found six pages drifted, traced to two upstream root causes plus two standalone fixes:.envsupport arrived for vars the docs called process.env-only:config.tsnow falls back to.envforCONTAINER_CPU_LIMIT,CONTAINER_MEMORY_LIMIT, and the three egress vars — corrected onreference/environment-variables,operate/configuration,operate/hardening, andoperate/troubleshooting.WEBHOOK_PORTis the exception and stays documented as process.env-only.- Five env vars removed upstream (the host-sweep loop replaced the old timeout/concurrency machinery):
CONTAINER_TIMEOUT,IDLE_TIMEOUT,MAX_CONCURRENT_CONTAINERS,CONTAINER_MAX_OUTPUT_SIZE,MAX_MESSAGES_PER_PROMPT— dropped fromreference/environment-variables,operate/configuration,operate/hardening, andguides/multi-agent-swarm. - Security correction (
operate/hardening): thereadOnlykey on additional mounts is no longer silently ignored —mount-securityhonors it, so{readOnly: false}grants read-write. The page said the opposite, understating permissiveness. reference/skills-catalog: 47 → 48 skills (/add-clidash)verified-againstanchors bumped to08a1ac9on the touched pages
Follow-up to the 2026-06-29 rework, aimed at the remaining beginner friction:
introduction— plain-language page description (was architecture jargon); new “What can it do?” section with six concrete, code-verified capabilities; the message-flow diagram and design rationale compressed into a short “Under the hood, briefly” paragraph linking toconcepts/architecture(which covers it in depth) — the intro no longer duplicates itquickstart— new “Things to try first” section: six copy-paste messages exercising web research, reminders, sandboxed code, inbound attachments, persistent memory, and companion agents, each verified against source (web tools are on the Claude provider’s allowlist;schedule_taskroutes back to the originating chat; attachments land in the session inbox;CLAUDE.local.mdpersists per group; the wizard’s first agent hasglobalCLI scope socreate_agentneeds no approval card). Includes the CLI-channel gotcha: reminders that fire while the terminal is disconnected are saved, not pushed live- Placeholder (comment) for a hero chat screenshot on
introduction, pending a capture from a live install
Brought the site current with
nanocoai/nanoclaw@cb6e3d1 (v2.1.23) and channels@90dd87d — a 14-commit trunk delta plus two channels-branch merges since the v2.1.21 sweep.- Inbox symlink-containment guard (
concepts/security): documented the new shared host-write guardsrc/inbox-safety.tsunder Container isolation — the one place files flow into the sandbox ncl messaging-groups --instance(reference/ncl-cli): new flag row — string, updatable, defaults to the--channel-typevalue- WhatsApp media recovery (
channels/whatsapp): failed inbound media downloads retry via WhatsApp’s re-upload path; still-failing media leaves a visible[<type> could not be downloaded]note instead of a silent drop - Slack Socket Mode in guided setup: upstream’s setup wizard caught up with what
channels/slackalready documented — the page verified accurate as-is, no content change - Full SHA re-verification: classified every page’s cited files against the trunk and channels diffs, re-verified the dirty set, and bumped
verified-againstanchors site-wide tocb6e3d1/90dd87d; fixed a transposed-digit providers-branch anchor (c576766→c570766) onextend/providers. Codebase token count 199k → 204k
Reworked the on-ramp to lead with outcome before architecture.
introduction now opens with what NanoClaw does for you (text it like a coworker; it runs code in a sandbox) and a “Key terms” callout defining agent / channel / sandbox / provider; the SQLite-queue framing moved into “How a message flows” rather than the lede. quickstart gained a time/effort/prerequisite expectation-setter. No facts changed — resequenced and scaffolded.Documented Slack’s Socket Mode (now the setup default) across
channels/slack and channels/overview. Setting SLACK_APP_TOKEN (xapp-…) opens an outbound WebSocket, so the host needs no public URL — alongside the existing webhook mode. Reverses the page’s old “v2 doesn’t use Socket Mode” note and the webhook-only framing.Brought the whole site current with
nanocoai/nanoclaw@2afbd182 (v2.1.21) after a drift check found the docs anchored at v2.1.16.- Agent-to-agent approval policies (migrations 017/018): documented the per-message gate on connected agents (the new
ncl policiesresource, theagent_message_policiestable), the strict named approver (approver_user_id), and reject-with-reason acrossguides/multi-agent-swarm,concepts/security,reference/{db-schema,ncl-cli},operate/ncl-cli, andextend/self-modification. - Codex provider v2 (
extend/providers): install via thecli-tools.jsonmanifest, vault-only auth, composedAGENTS.md+.agents/skills+ per-group~/.codex. Removed the stale.env/OPENAI_BASE_URLclaims. - Container resource caps +
/learn:CONTAINER_CPU_LIMIT/CONTAINER_MEMORY_LIMITadded toreference/environment-variables,operate/{configuration,hardening}, andconcepts/container-lifecycle; the/learnskill added toreference/skills-catalog(46 → 47) andextend/writing-skills. - Upgrade flow (
operate/upgrading):/update-nanoclawnow upgrades the OneCLI gateway when itsversions.jsonpin moves (reversing the old “never upgraded for you”), and/update-skillsrebuilds the container image when re-applied code lives undercontainer/. - Provider-aware install (
installation,quickstart): the credential prerequisite is now “a credential for the provider you pick,” not Claude-only. - Full SHA re-verification: re-verified every cited file’s diff e3986eb..2afbd182 and bumped the
verified-againstanchor on ~30 pages; bumped thechannelsregistry branch tofdbfb6aand refreshed the channel-adapter pins to4.29.0(Chat SDK lock). Codebase token count 195k → 199k.
changelog/index.mdx jumped straight from v2.0.0 to v2.1.5. Reconstructed the ~80 intervening patch releases by mapping upstream version bumps, mirroring upstream’s own granularity rather than fabricating per-patch detail.- Milestone entries for the versions upstream’s
CHANGELOG.mddocuments — thencladmin CLI + v1→v2 migration (2.0.45), container-config-in-DB +cli_scope(2.0.48), per-group model/effort (2.0.54), the per-install-service-names breaking rollup (2.0.55–2.0.63), the destinations-through-approval fix (2.0.64), and the startup upgrade-marker breaking change (2.1.0) - Egress lockdown reconstructed for v2.1.1 from commits; honest rollups for the rapid-patch ranges (2.0.1–2.0.44 stabilization, 2.0.65–2.0.76) with a pointer to GitHub releases
- Every version 2.0.1–2.1.4 is now accounted for in a labeled entry. Closes the last known gap noted in the v2.1.16 sweep
Neutralized prose where “Claude” stood in for “the agent” generically — claims that read as false on a non-Claude (Codex/OpenCode/Ollama) group. Claude-specific facts and literals (the Claude Code CLI, the Claude Agent SDK,
CLAUDE.local.md, Claude credentials) are kept verbatim.extend/tools.mdx: the local-model tool skills keep the agent as the orchestrator (not “Claude”)guides/scheduled-tasks.mdx: a firing is “a full model API call” / “the agent got called”reference/mcp-tools.mdx: “the tools the agent can call” (dropped the(Claude)parenthetical);create_agentseeds the provider’s own memory surface (CLAUDE.local.mdfor Claude, thememory/scaffold otherwise), matching themulti-agent-swarmfixinstallation.mdx: the wizard does “provider auth”;quickstart.mdx: “AI-assisted recovery” (failure assist can be provider-owned since v2.1.16)
Brought the whole site current with
nanocoai/nanoclaw@e3986eb (v2.1.16) — every content page is now anchored at v2.1.16.- Product changelog + token count: added the v2.1.16 release (operator-driven provider selection, per-group provider switching via
ncl groups config update --provider, and/migrate-memory) and bumped the codebase token count to 195k. - Provider selection (16 v2.1.15 pages): documented the setup-time runtime picker (
quickstart), the memory-across-a-switch story and/migrate-memory(extend/providers), and fixedmulti-agent-swarm(a spawned agent inherits its creator’s provider; the seed lands in the provider’s own memory surface) andupgrading(the/update-nanoclawbreaking-change check is skill-only now — it no longer diffsversions.jsonpins). Corrected six driftedfile:linecitations onreference/environment-variables. - Re-verified the 19 v2.1.4 main pages: 14 were no-drift; 5 fixed —
installation(newprovider-authsetup step),concepts/contributing(185k → 195k, vitest globs),reference/skills-catalog(added/migrate-memory; 45 → 46 skills),operate/troubleshooting(boot failures now logContainer exited non-zerowith astderrTail),extend/overview(provider installs span three barrels now — host, container, and setup). - Re-verified the 8 channel pages: the
channelsregistry branch is frozen at8137440(adapters unchanged since before v2.1.4), so no content drift — pinned that SHA on each page for precise future adapter-drift detection.
Closed out the v2.1.4 → v2.1.15 drift sweep.
changelog/index.mdx: reconstructed the v2.1.5–v2.1.15 product releases from upstream commits (the upstreamCHANGELOG.mdstill parks everything under[Unreleased]). v2.1.5 was the big one — multi-instance adapters and the interactive uninstaller- Re-verified and bumped
verified-againstSHAs to435233aon pages whose cited files changed without any claim drifting:concepts/architecture,reference/container-config,guides/scheduled-tasks,concepts/isolation-levels,guides/multi-agent-swarm channels/teams: corrected the webhook-path note to/webhook/{routingPath}to match the raw-route change- Known gap: the product changelog still jumps v2.0.0 → v2.1.5; the v2.0.1–v2.1.4 patch releases predate the docs site and remain unreconstructed
v2.1.15 added an interactive uninstaller (
bash nanoclaw.sh --uninstall). New operate/uninstall.mdx documents it, verified against nanocoai/nanoclaw@435233a.- The scan → confirm → execute flow, the four removal groups, and what’s deliberately left alone (the OneCLI vault, other NanoClaw copies — everything is scoped to the per-checkout install slug)
- The
--dry-runand--yesflags, the.envbackup, the Ctrl-C-safe confirm phase, and the manual fallback whennode_modules/is already gone - Resolved a flag-spelling discrepancy against source: the flags are
--dry-run/--yes(kebab-case), and they’re CLI-only — there are noNANOCLAW_*env vars for them reference/environment-variables.mdxre-verified (no env var drift in v2.1.15) and its SHA bumped
v2.1.15 moved
@onecli-sh/sdk to 2.x, which talks to the OneCLI gateway’s /v1 API, and introduced versions.json as the machine-checkable source for sanctioned component pins. Verified against nanocoai/nanoclaw@435233a.operate/credentials.mdx: setup installs the gateway andonecliCLI at theversions.jsonpins (onecli-gateway,onecli-cli), neverlatest; it probes/v1/healthand warns (never auto-upgrades) when the gateway predates the/v1API, pointing to thedocs/onecli-upgrades.mdrunbookoperate/upgrading.mdx: the/update-nanoclawbreaking-changes step now also diffsversions.jsonfor moved component pins and routes each to its migration path — a skill or adocs/page
v2.1.15 added provider-agnostic capability hooks so a non-Claude provider can plug into NanoClaw without special-casing. Documented on
extend/providers.mdx, verified against nanocoai/nanoclaw@435233a.usesMemoryScaffold: a provider without native memory opts in, and the runner builds an idempotentmemory/tree (index.md,system/definition.md,memories/,data/) in the agent’s host-backed workspace at boot. Claude omits it — it already has native memory (CLAUDE.local.md).onExchangeComplete: the poll loop hands each prompt/result round-trip to providers whose harness keeps no on-disk transcript, so they can archive exchanges themselves.providesAgentSurfaces: a provider can declare it owns the composed project doc, skill links, and state dir; the host then skips the default surfaces and the provider composes its own.- Same pass nudged the page’s voice provider-neutral (Claude framed as the default, not the only brain).
v2.1.15 lets you run several adapters of one platform at once (e.g. three Slack apps in one workspace). A new
instance dimension threads through the stack, and the docs now describe it where it lands. Verified against nanocoai/nanoclaw@435233a.reference/adapter-interface.mdx: new optionalinstancefield on theChannelAdaptercontract (defaults tochannelType; URL-safe routing key);channelTypeclarified as the semantic platform key; webhook registration now uses aroutingPathand the shared server also accepts rawregisterWebhookHandler()routesreference/db-schema.mdx+concepts/entity-model.mdx:messaging_groupsis now keyed(channel_type, platform_id, instance); documented the newinstancecolumn, migration 016’s backfill (instance = channel_type), and the per-instancechat_sdk_kvkey prefixchannels/overview.mdx+concepts/architecture.mdx: webhook server routes byroutingPathwith raw handlers taking priority; delivery resolves the owning adapter byinstanceso a reply leaves through the adapter the message arrived on
First slice of re-verification against upstream
nanocoai/nanoclaw@435233a (v2.1.15, up from v2.1.4). Two code-confirmed factual corrections shipped; larger concerns (multi-instance adapters, provider memory scaffold, OneCLI /v1 upgrade, the new uninstall flow) follow in separate PRs.introduction.mdx: codebase token count ~185k → ~194k (verified againstrepo-tokens/badge.svg)installation.mdxandconcepts/container-lifecycle.mdx: the container’s pinned global CLIs now come from acontainer/cli-tools.jsonmanifest installed byinstall-cli-tools.sh—agent-browseris pinned to an exact version rather than trackinglatest
Phase A of the v2 documentation sprint — bringing the pages every new user lands on into alignment with the v2 rewrite. All claims verified directly against upstream source (
src/db/schema.ts, src/types.ts, src/config.ts, container/Dockerfile, src/delivery.ts) rather than upstream docs/ (which includes a stale architecture.md draft and a db-session.md that omits the container_state table).Rewritten
introduction.mdx: v2 positioning — two-DB session IO, entity model, Node + Bun runtime split, OneCLI-only credentials. Token count updated to ~127k (~64% of context window). Source file table aligned withsrc/as of v2.0.1.quickstart.mdx: one-commandbash nanoclaw.shflow replaces the v1 fork-and-clone + Claude Code +/setupdance. Documents the three-level setup log contract (terminal,logs/setup.log, per-step raw logs) and the Anthropic OAuth exception.installation.mdx: simplified to system requirements + platform prerequisites +bash nanoclaw.sh. Service management retained (launchd / systemd / WSL wrapper). File-structure tree updated fordata/v2-sessions/,store/v2.db, and the per-sessioninbound.db+outbound.dblayout.integrations/overview.mdx: reframed around channels (13+) and providers (4), both living on dedicated branches (channels,providers). Expanded channel list to cover Teams, iMessage, Matrix, Google Chat, Webex, Linear, GitHub, WeChat, Resend, and the local/clawCLI.features/customization.mdx: full v2 rewrite — verified trigger pattern code againstsrc/config.ts, replaced nonexistentPOLL_INTERVAL/SCHEDULER_POLL_INTERVALwith actualACTIVE_POLL_MS/SWEEP_POLL_MSfromsrc/delivery.ts, documented per-wiring engage config (engage_mode,sender_scope,ignored_message_policy,session_mode), kept OneCLI / legacy credential proxy as version tabs.
v2 update banners
Added<Warning> banners to pages pending a v2 rewrite (channel adapters moved to a single channels branch in v2, not per-channel skill/* branches):integrations/whatsapp.mdx,telegram.mdx,discord.mdx,slack.mdx,gmail.mdx,x-twitter.mdx,skills-system.mdxintegrations/ollama.mdx(Ollama now lives on theprovidersbranch —/add-ollama-provideror/add-ollama-tool)
Token count sync
integrations/skills-system.mdx: 43.8k → 127kCLAUDE.md: maintenance note updated to reflect the v1.2.53 → v2.0.0 jump
Merged PR #187 — comprehensive rewrite of concepts, advanced, api, and features pages for the v2.0.0 ground-up architectural rewrite (nanocoai/nanoclaw#1919). Closed PRs #184, #185, #186 as superseded.
Updated
- Two-database session model:
inbound.db(host writes) +outbound.db(container writes) replace stdin/stdout piping and filesystem IPC — documented acrossconcepts/architecture,advanced/ipc-system,advanced/container-runtime - Entity model: agent groups, messaging groups, wirings (many-to-many), users, and roles replace the v1 group/channel model — new
concepts/groupsandapi/group-management - Bun-based agent runner: runs TypeScript directly (no compilation), shared source via read-only bind mount,
tinias PID 1 —concepts/containers,advanced/container-runtime - Permissions system: engage modes (pattern/mention/mention-sticky), sender scope (all/known), unknown sender policies (strict/request_approval/public), approval flows —
concepts/security,advanced/security-model - Delivery system: two-poll architecture (active 1s, sweep 60s) with delivery action registry —
features/messaging - Task model: tasks as
messages_inrows with cron recurrence and series tracking —concepts/tasks,features/scheduled-tasks,api/task-scheduling - OneCLI Agent Vault is the sole credential path; legacy credential proxy removed —
advanced/security-model,api/configuration - Changelog: v2.0.0 release entry
Archived
- v1 docs frozen at branch
v1-docs(public-facing, docs only) and tagv1-docs-final(full repo snapshot)
Updated
- Token count: Updated from 43.7k to 43.8k in introduction and skills-system pages
- Configuration: Added
ONECLI_API_KEYenv var to OneCLI Agent Vault tab - Container SDK config: Documented
allowDangerouslySkipPermissions: trueflag in containers page - Changelog: Added v1.2.53 product release entry
Updated
- Token count: Updated from 43.4k to 43.7k in introduction and skills-system pages
- Changelog: Added v1.2.48–v1.2.52 product release entries
- Skills system: Added
/add-karpathy-llm-wikito upstream skills listing; added/migrate-nanoclawand/migrate-from-openclawto operational skills - Troubleshooting: Added session artifact auto-pruning section with retention policy table
- Architecture: Documented auto-compact threshold at 165k tokens
Triaged 3 automated Mintlify PRs (#175–#177). Merged #177 (most comprehensive), closed #175 and #176 (superseded). Cherry-picked unique content from closed PRs.
Updated
- Store mount (rw): Documented
store/read-write mount for main agent across containers, container-runtime, security, security-model, groups, customization pages requiresTriggerparameter: Added toregister_groupMCP tool description in containers and messaging pages- Reply context: Updated architecture database section with
reply_to_message_id,reply_to_message_content,reply_to_sender_namecolumns isMainpreservation: Updated register_group handler snippet in messaging pageCONTAINER_MAX_OUTPUT_SIZE: Added truncation behavior note to configuration reference- Token count: Updated from 43.3k to 43.4k in introduction and skills-system pages
- Changelog: Added v1.2.46 and v1.2.47 product release entries
quickstart: Added breaking change changelog scan to/update-nanoclawstep listintegrations/skills-system: Added “Breaking change detection” subsection documenting the[BREAKING]entry scan and migration skill prompts
Fixed
concepts/containers: Removed incorrect “15-second exec timeout” claim fromstopContainer— the source usesexecSyncwith no timeout, falling back toSIGKILLon failure
Updated
integrations/skills-system: Added/add-macos-statusbarutility skill to upstream skills listingchangelog/index: Added v1.2.45 release entry with new contributors and skill
Reviewed and triaged 8 automated Mintlify PRs (#161–#168). Merged 4, closed 4 (superseded or stale token counts). Validated all changes against upstream source code at v1.2.46. Deleted 11 stale branches (4 PR + 7 orphan).
Updated
- OneCLI version labels: Corrected Agent Vault version from v1.2.22+ to v1.2.35+ across 8 pages, added tabbed 401 troubleshooting
- Ollama integration: Added 4 admin tools (
ollama_pull_model,ollama_delete_model,ollama_show_model,ollama_list_running) gated byOLLAMA_ADMIN_TOOLS=true, noted Ollama removal from core - Stale session recovery: Added auto-recovery docs to troubleshooting and container-runtime lifecycle, plus manual sqlite3 fallback
- Container runtime: Documented
hostGatewayArgs(),--add-hostflag,curl/gitin container image - SDK options: Added
settingSourcesandsenderparameter docs - Reply context: Documented reply/quoted message support —
reply_toattribute,<quoted_message>element, 4 newNewMessagefields, DB migration - Token count: Updated from ~42.4k to ~43.3k (22%)
- v1.2.43 changelog: Added npm audit dependency fixes bullet
Merged automated health check PR #158 (4 of 5 fixes verified against upstream). Corrected the remaining inaccurate claim in a follow-up (#159).
Fixed
api/message-routing: Removed phantomchannel?: ChannelTypeparam fromformatOutboundsignaturefeatures/scheduled-tasks: Updated TIMEZONE snippet to currentresolveConfigTimezone()with IANA validation and UTC fallbackadvanced/container-runtime: FixedstopContainercode from asyncexec()callback to actual sync try/catch patternapi/configuration: Addedtraceas validLOG_LEVELvalue (used by container runner for verbose output)features/messaging: Corrected stalesrc/session-commands.tsreference tosrc/index.ts, and fixed misleading description of whatindex.tsdoes
Updated
advanced/remote-control: Fixed inaccurate security section — the remote control URL requires Anthropic sign-in, not just URL secrecy. Based on feedback from Gavriel Cohen.
Reviewed and triaged 27 automated Mintlify PRs (#92–#151). Merged 6, consolidated 7 into a single verified PR (#153), closed 15 (superseded, fabricated, or conflicting). Validated all changes against upstream source code at v1.2.42. Deleted 41 stale
mintlify/* branches.Updated
- OneCLI rebrand: Renamed “OneCLI Gateway” to “OneCLI Agent Vault” across 15 pages, updated URL to
github.com/onecli/onecli. Code snippets preserved as-is (upstream source still uses “gateway” in code). - Message limits: Corrected 200-message cap to
MAX_MESSAGES_PER_PROMPT(default 10) across messaging, architecture, and configuration pages - Dependencies: Removed phantom deps (
pino,pino-pretty,yaml,zod), updatedbetter-sqlite3to11.10.0andcron-parserto5.5.0 - Token count: Updated from ~41.3k to ~42.4k
- Mount property: Fixed
containerConfig.mounts→additionalMountswithhostPath - SQL column: Fixed
trigger→trigger_patternin troubleshooting query - Product changelog: Added entries for v1.2.35 through v1.2.42
New sections
- Telegram forum topics (
integrations/telegram) —message_thread_idtracking and automatic topic routing - Task scripts cost guidance (
concepts/tasks,features/scheduled-tasks,api/task-scheduling) — API credit awareness, testing guidance, when-not-to-use advice - Auth 401 troubleshooting (
advanced/troubleshooting) — short-lived vs long-lived OAuth tokens,claude setup-tokenfix - K8s image GC (
advanced/troubleshooting) — Rancher Desktop kubelet garbage collection known issue - Text-style formatting (
features/messaging) — corrected WhatsApp link rendering and Telegram Markdown v1 preservation - Security fixes (
advanced/container-runtime,advanced/security-model,concepts/security) —stopContainername validation, mount path colon rejection,isMainpreservation, allowlist caching behavior - Configuration: Added
MAX_MESSAGES_PER_PROMPTandLOG_LEVELenvironment variables - Skills: Added
/init-onecli(operational) and/add-emacs(upstream)
Closed as invalid
- #150: Fabricated runtime-based credential routing — no such feature exists in upstream
- #149: Wrong
context_modedefault (groupinstead of actualisolated) - #134: Promoted skill-only
OLLAMA_ADMIN_TOOLSenv var to core config
Reviewed and triaged 43 automated Mintlify PRs (#86–#128). Merged 8, closed 30 (superseded or inaccurate), kept 5 pending v1.2.35 release. Validated all changes against upstream source code at v1.2.34.
New sections
- Task scripts (
concepts/tasks,features/scheduled-tasks,api/task-scheduling) — pre-execution bash scripts withwakeAgentJSON contract,ScriptResulttype, execution flow - Per-group trigger patterns (
features/messaging,concepts/groups,api/configuration) — custom trigger words per group instead of global@{ASSISTANT_NAME} - CLAUDE.md template system (
concepts/groups,api/group-management) — automatic template copy during registration withisMain-based selection - Channel-formatting skill (
features/messaging,api/message-routing,integrations/slack,integrations/skills-system) — per-channel text transformation table - WhatsApp pairing code auth (
integrations/whatsapp) — tabbed QR code vs pairing code with phone number formatting rules - loginctl linger (
installation,quickstart,advanced/troubleshooting) — systemd user service persistence after SSH logout - Mount-allowlist preservation (
quickstart,advanced/troubleshooting) —/setupskips overwrite of existing config
Updated
- Container base image: Fixed
node:24-slim→node:22-slimacross 6 pages (v1.2.22 changelog never upgraded to Node 24) - Timezone configuration: Added
resolveConfigTimezone()with IANA validation and UTC fallback across 4 pages - Token count: Updated from ~39.8k to ~41.3k in introduction and skills system pages
- Agent-runner cache: Documented mtime-based refresh instead of one-time copy
- Customization: Removed phantom
MAIN_GROUP_FOLDERconstant - Product changelog: Added entries for v1.2.24 through v1.2.34
Closed as invalid
- #125: Fabricated upstream PR #1346 as “stdin secrets / remove OneCLI” — actual PR is macOS menu bar status indicator
- #119: Destructively removed credential proxy legacy tabs that are intentionally maintained
- #88: Incorrectly documented
senderas IPCsend_messageparameter (it’s aNewMessagefield) - #89: Falsely claimed Telegram is a core channel on main (it lives in
nanoclaw-telegramfork)
Merged 3 automated PRs syncing docs with v1.2.23 upstream changes (#82, #84, #85). Closed #83 (would have removed legacy credential proxy tabs).
Updated
- Legacy credential proxy tabs: Updated to reference
/use-native-credential-proxyskill instead of deletedsrc/credential-proxy.tsfile path - Skills system: Added
/use-native-credential-proxyto upstream skills list - Architecture: Fixed startup sequence order (OneCLI agent sync before Remote Control restore), enriched database schema descriptions
- IPC system: Documented in-container poll interval (500ms), removed undocumented
senderfield - Containers: Fixed
.envshadow mount to note conditional existence check, clarified container stop timeout cascade - Configuration and installation: Added
onecli --helpreferences - Introduction and skills system: Updated token count from ~41k to ~39.8k
- Product changelog: Updated v1.2.23 entry with credential proxy skill and dead code cleanup
Added tabbed documentation for OneCLI Agent Vault secret injection (v1.2.22+) alongside legacy credential proxy across 9 pages. Added OneCLI as installation prerequisite.
Pages updated
- Security overview and deep dive: Credential handling sections now use tabs for OneCLI Agent Vault vs Credential Proxy (legacy)
- Configuration: Environment variables, example
.env, and security notes updated with tabs - Container runtime: Container arguments code and key flags documented for both methods
- Architecture: Startup sequence and container image updated
- Installation: OneCLI added as prerequisite #5,
@onecli-sh/sdkdependency - Containers, Ollama, Skills examples: Passing references updated to version-neutral language
- Customization: Mount allowlist format updated (
allowedPaths→allowedRootswith per-root read/write control) - Product changelog: Added v1.2.22 release entry and v1.2.0 scheduled task fix
Audited documentation in the upstream NanoClaw repo against the docs portal and submitted fixes via nanocoai/nanoclaw#1388.
Updated
- Installation, introduction, creating-skills: Added Windows (WSL2) to all platform references — NanoClaw supports macOS, Linux, and Windows via WSL2
- Introduction: Fixed token count from 34.9k to ~41k (matches auto-generated
repo-tokens/badge.svg) - CLAUDE.md: Added guidance for automated PR triage, changelogs, upstream PR workflow, and token count source of truth
Upstream PR (#1388)
- Added
docs.nanoclaw.devlink to README header - Populated CHANGELOG.md with all releases from v1.1.0 through v1.2.21
- Updated
docs/REQUIREMENTS.md— multi-channel support, current RFS, WSL2 deployment - Updated
docs/SECURITY.md— channel-neutral language - Updated
docs/DEBUG_CHECKLIST.md— Docker (default) commands, channel-neutral - Added
docs/README.md— index pointing to docs portal as authoritative source
Reviewed, triaged, and consolidated 10 automated Mintlify PRs (#60–#69). Verified all changes against NanoClaw source code, excluded 6 incorrect changes, and resolved the final 2 open issues.
New pages
- Claw CLI (
features/cli) — documents the/clawPython CLI for running agents from the command line (#64)
New sections
- Apple Container vs Docker (
advanced/container-runtime) — when to use each runtime, key differences table, switching instructions (closes #50) - Container internals (
concepts/containers) — allowed tools table, conversation archival, global memory injection, additional directory auto-discovery - Slack message formatting (
integrations/slack) — mrkdwn syntax differences and/slack-formattingskill - 200-message history cap (
features/messaging) — documents the default query limit on message retrieval (closes #49) - Opt-in diagnostics (
concepts/security,quickstart) — PostHog telemetry, consent flow, permanent opt-out (#68)
Updated pages
- Skill system — updated from 3 to 4 skill types (feature, utility, operational, container) across 6 pages
- Skills documentation — added utility skill structure, creation steps, and
/clawas example - Architecture — fixed database table names (
scheduled_tasks,task_run_logs),isScheduledTaskflag, stdin description, startup sequence expansion - Message routing — added
syncGroupsto Channel interface - Configuration — fixed DATA_DIR description (runtime data, not legacy)
- Skills system — added missing skills (
/get-qodo-rules,/qodo-pr-resolver,/x-integration,/add-compact,/add-parallel,/slack-formatting) - Contributing — removed
/clearfrom RFS (exists as/add-compact), updated to 4 skill types - SEO descriptions — improved frontmatter across 10 pages for better search discoverability
Fixed
- 13-page factual error sweep against source code (#67) — credential proxy terminology, IPC operations, container mount behavior, removed phantom MCP tool
- Consolidated overlapping fixes from 6 PRs into 2 clean PRs (#70, #71), closing 7 automated PRs as superseded
- Excluded incorrect automated changes: Channel Factory rename, fabricated commit reference, speculative formatting table, unverified frontmatter claims
Housekeeping
- Product changelog: added v1.2.20 (ESLint) and v1.2.21 (diagnostics) entries, fixed version ordering
- Resolved all open issues — 0 issues remaining
- Token count updated from “under 35k” to “~41k”
Ran a full docs-gap analysis against the upstream codebase and resolved 13 of 15 content-gap issues. Two low-priority items remain open (#49, #50).
New pages
- Ollama integration (
integrations/ollama) — MCP server architecture, local model setup, third-party endpoints - Voice transcription (
features/voice-transcription) — Whisper API (cloud) and whisper.cpp (local) with comparison table - Image vision (
features/image-vision) — Multimodal image understanding for WhatsApp - PDF reader (
features/pdf-reader) — Text extraction via poppler-utils - X (Twitter) integration (
integrations/x-twitter) — Host+agent architecture, OAuth setup - Parallel AI (
integrations/parallel-ai) — Web research MCP servers (quick search + deep research)
Updated pages
- Skills system — Documented channel fork architecture (5 fork repos), updated merge workflows, separated upstream vs fork skills
- Installation — Added Windows (WSL) support across all sections: prerequisites, Docker Desktop WSL 2 backend, troubleshooting
- Security — Documented sender allowlist: trigger/drop modes, per-chat overrides, file format
- Messaging — Added
/compactsession command and authorization rules - Telegram — Expanded agent swarm section with installation and per-bot config
- WhatsApp — Added skills summary table and emoji reactions section
- API reference — Fixed
formatMessagessignature (addedtimezoneparam and<context>header) - Configuration — Added
OLLAMA_HOST, expandedANTHROPIC_BASE_URLandSENDER_ALLOWLIST_PATHdocs
Housekeeping
- Deleted 6 stale
mintlify/*branches - Created tracking issues for 3 remaining low-priority gaps (#49, #50)
Corrected 30+ inaccuracies across 12 documentation pages by auditing against the NanoClaw source code.
- Fixed credential proxy documentation — removed incorrect claims about hot-swapping and auto-refresh
- Corrected container runtime detection, base image references, and stdin secrets pattern
- Updated task scheduling docs with correct table names and interfaces
- Added missing
.envshadow mount andCREDENTIAL_PROXY_HOSTdocumentation - Fixed
syncGroupMetadata→syncGroupsacross IPC docs
- Updated error log examples to show prompt redaction — input metadata only, no full prompt content
- Added log privacy section to security docs
- Corrected
docker stopgrace period from 15s to 1 second across all references
- Fixed remote-control commands documentation
- Deduplicated IPC docs
- Added
update_taskto auth tables in API reference
- Added automatic sidebar tag management via Mintlify workflows (
UPDATEDandNEWtags) - Replaced all ASCII directory trees with Mintlify
<Tree>component across the site - Tags auto-clean after 2 weeks via weekly audit workflow
Fixed rendering issues and remaining WhatsApp-as-default framing reported in issues #14–#18.
- Documented
/capabilitiesand/statuscontainer-agent skills as new pages - Synced docs with source code v1.2.17 — corrected mount allowlist format, interval drift handling, credential proxy behavior, and IPC config
- Documented IPC task snapshot refresh and
update_taskoperation
Fixed stale documentation for credential proxy, database path, mount allowlist, and task lifecycle to match current source code.
- Added Mintlify workflow to sync docs automatically on upstream code changes
- Added weekly docs audit and skill branch documentation workflows
- Applied NanoClaw branding with custom theme colors, fonts, and SEO metadata
- Switched theme from Aspen to Mint for better sidebar typography
- Cleaned up introduction page, footer, and removed callout CSS override
Launched docs.nanoclaw.dev — the NanoClaw documentation site built with Mintlify.
- Audited all content against v1.2.14 codebase
- Added Remote Control and Docker Sandboxes pages
- Made quickstart channel-agnostic (removed WhatsApp-as-default bias)
- Updated skills documentation to reflect git-branch architecture
- Fixed navigation structure with logical page ordering
- Added Mintlify skill for consistent docs development