Repository navigation
Releases: Lord1Egypt/PocketClaw
Release list
PocketClaw v0.2.3 — Golden #4
A security and build-hardening release for Android. It is the fourth fully validated build of PocketClaw ("Golden #4"): built from the tagged source in the same pinned environment F-Droid uses to rebuild apps, signed with the production key, and physically accepted on a Samsung phone running Android 16 before publication.
Highlights
- Security update. PocketClaw's background core is now built with a current, supported Go release (1.26.8) and updated libraries that fix known vulnerabilities.
- GitHub CLI 2.101. The bundled
ghtool is updated from 2.82.1 to 2.101.0. - Build hardening in preparation for F-Droid. The app and all of its bundled tools are built entirely from source in a pinned, repeatable environment. Two independent clean builds of this release produced the identical APK, and F-Droid's own verification accepts this signed APK as a match for its rebuild.
- Clearer description. PocketClaw never downloads its runtime after install; the bundled tools, and skills from the ClawHub registry or GitHub, use the network only when you ask the agent to.
PocketClaw is not yet listed on F-Droid.
Requirements
- Android 8.0 (API 26) or newer.
- An
arm64-v8adevice.
Upgrading over 0.2.2 keeps your data, configuration and workspace in place. It installs over the published 0.2.2 build because both are signed with the same key.
Verify this download
sha256sum -c SHA256SUMS.txt
PocketClaw-v0.2.3-arm64-v8a.apk — 58,441,695 bytes
778882828e2f818aac31ed1f58dd3b2e8530828970b535ce72564f5ed2857599
Signing certificate SHA-256:
176dca6b198b9552fb4d9ad3ca18da8d6f23c0a3f5ed4bd6b75a0700f9f0efcf
Check the signer with apksigner verify --print-certs PocketClaw-v0.2.3-arm64-v8a.apk.
PocketClaw v0.2.2 — Golden #3
A reliability and cleanup release for Android. It is the third fully validated build of PocketClaw ("Golden #3"): built from the tagged source, signed with the production key, and physically accepted on a Samsung phone running Android 16 before publication.
Highlights
- No more crash after restarting the phone. Fixed an Android startup crash that could appear after a reboot, before PocketClaw was even opened.
- Long tasks over Telegram. After a long task the answer arrives as a new message, so it notifies you and appears below anything you sent meanwhile. Short replies still update in place.
- Queued messages are visible. Messages sent while PocketClaw is busy get a short "Queued — N messages ahead" note, are answered in order, and the note disappears when their turn starts.
- Huge tool output is contained. Very large command output is trimmed before it reaches the model, so a turn no longer fails with a request-too-large error.
- Workspace in app storage. The workspace lives in PocketClaw's own storage and the app asks for no storage permission. A workspace an older version left in
Download/pocketclawis never touched automatically and can be copied in from Settings; an empty folder there is ignored. - Cleaner Android settings. Settings that did nothing on Android (Devices, Launch at Login, Service Port and a few desktop-only fields) are gone.
- Arabic and right-to-left fixes. File paths keep their slashes in place, a blank gap in Settings is gone, and the Dashboard header no longer clips its buttons on a phone.
- Dashboard on phones. Page headers wrap instead of cutting off actions such as "Add Provider", and the floating back/forward/reload control no longer covers the Dashboard menu.
- What's New keeps its history. The screen shows every release, newest first; older releases open in place.
- Branding. The app icon, notification mark and README use the same PocketClaw mark.
- Privacy. The embedded web view is opted out of its own usage metrics.
Requirements
- Android 8.0 (API 26) or newer. This release raises the minimum from Android 7.0: parts of the background service need Android 8.0, so older versions could not start it.
- An
arm64-v8adevice.
Upgrading over 0.2.1 keeps your data, configuration and workspace in place. It installs over the published 0.2.1 build because both are signed with the same key.
Verify this download
sha256sum -c SHA256SUMS.txt
PocketClaw-v0.2.2-arm64-v8a.apk — 61,346,447 bytes
320368eaf1c3c48689625e02764a658e3ed291d4c6e49b3d67ed09326dd58af9
Signing certificate SHA-256:
176dca6b198b9552fb4d9ad3ca18da8d6f23c0a3f5ed4bd6b75a0700f9f0efcf
Check the signer with apksigner verify --print-certs PocketClaw-v0.2.2-arm64-v8a.apk.
PocketClaw v0.2.1
Patch release fixing the bundled Git on Android.
Fixes
- The bundled Git no longer crashes while cloning a repository or updating a branch.
Details
A native crash in the bundled Git ended any operation that wrote a reference
log, so git clone died partway through and creating or switching branches
failed. Cloning, branch and reference operations, and reflogs all work normally
again.
The fix is Git's own Android portability configuration, so no workaround is
needed and reflogs stay enabled — nothing has to be disabled to make Git work.
No workspace migration and no storage-policy change are included in this
release. Upgrading over 0.2.0 keeps your data in place.
Verify this download
sha256sum -c PocketClaw-v0.2.1-SHA256SUMS.txt
PocketClaw-v0.2.1-arm64-v8a.apk — 63,613,115 bytes
1203cd46f30cc6e7d69b3cd54be2d2dbca29150a9bce4f722b112576ccf4401b
Signing certificate SHA-256:
176dca6b198b9552fb4d9ad3ca18da8d6f23c0a3f5ed4bd6b75a0700f9f0efcf
Android arm64-v8a.
PocketClaw v0.2.0
First stable PocketClaw release.
PocketClaw runs a local AI agent runtime on your Android device, with its own Dashboard for configuration and Telegram as a chat surface.
Highlights
- PocketClaw Android runtime — the agent runs on your device, as a foreground service you control.
- Local Dashboard — configure everything from the app, or from a browser on your own network.
- AI provider and model configuration — add a provider, rotate an API key, set a default model, remove a model.
- Telegram integration with managed onboarding — one-tap setup creates your own bot. There is no token to copy, and only your own account can talk to it. You can replace or disconnect the bot later from the Dashboard.
- Public Mode / LAN Dashboard — reach the Dashboard from another device on your network when you choose to.
- Runtime lifecycle hardening — one Core runtime, started and stopped predictably.
- Honest notification state — the persistent notification says PocketClaw is running only while it actually is.
- Telegram readiness and connection handling — "Connected" means Telegram is receiving, and a bot that is unreachable or already in use says so plainly.
- Provider default and key-rotation support — a replaced key reaches the running gateway without a manual restart.
- PocketClaw branding throughout — a clean product surface across the app, the Dashboard and the default workspace.
Notes
- This release is arm64-v8a.
- Credentials / account-login UI is intentionally deferred. Provider access is configured with API keys through Models.
- Google, Claude subscription and ChatGPT/Codex account login are planned for a future version.
Verifying this download
sha256sum -c PocketClaw-v0.2.0-SHA256SUMS.txt
Expected APK SHA-256:
c8d599517dcaf6b954691634c2eb2c5e5cd8c88200cb77cb21a7f5861439e28c
Signing certificate SHA-256:
176dca6b198b9552fb4d9ad3ca18da8d6f23c0a3f5ed4bd6b75a0700f9f0efcf
PocketClaw v0.2.0-rc3
PocketClaw's most complete 0.2.0 release candidate yet, with the new APERTURE
visual identity, improved managed runtime, stronger provider resilience,
secure GitHub integration, Telegram improvements, and live model discovery
from configured AI providers.
Highlights
New APERTURE interface
- Redesigned Android and Web experience
- New PocketClaw visual identity
- Improved mobile navigation
- Better responsive and RTL behavior
- Refined chat, models, settings and runtime surfaces
Configured-provider model discovery
- Default and Fallback model selectors now show models from providers you actually configured
- Live model discovery from supported provider APIs
- Discovered models can be configured directly from the picker
- Unconfigured built-in provider templates no longer clutter the model picker
- Provider failures are isolated so one failed provider does not hide another
Managed Runtime
- Bundled managed command-line tools
- Python 3.14 managed runtime
- Runtime catalog and payload validation improvements
GitHub integration
- Secure GitHub authentication
- Android Keystore-backed credential protection
- GitHub CLI integration without exposing tokens to the frontend
Telegram
- Improved request lifecycle behavior
- Bounded conversational context with rolling summary
- Configurable Telegram context length
- Better Thinking/typing cleanup and delivery reliability
Reliability
- Provider resilience improvements
- Stale runtime process handling
- Runtime/catalog consistency checks
- Multiple Android lifecycle and configuration fixes
Android
- Package:
com.lord1egypt.pocketclaw - Version: 0.2.0
- Version code: 41
- Architecture: ARM64
SHA-256:
4fd3c201bb9a07017a954ade90f5eb471b97d281e057a58fad4b7e18cf76e7ec PocketClaw-v0.2.0-rc3-arm64.apk
Status
This is a pre-release build intended for testing before the final PocketClaw
v0.2.0 release.
PocketClaw v0.2.0-rc2
PocketClaw v0.2.0-rc2 is the second release candidate. It is not the final production release and is not published to Google Play.
RC2 adds optional Auto-Start for the PocketClaw Service and the Core Gateway, and fixes an Android-specific false positive that could delete a running Gateway's PID file. It is a small, deliberately minimal change on top of v0.2.0-rc1: the earlier experimental Auto-Start branch was discarded rather than merged, and this implementation was rebuilt from the RC1 baseline.
Auto-Start
- Optional automatic PocketClaw Service startup and optional automatic Gateway startup, as two independent settings.
- Fresh installations default both to ON. Existing preferences are preserved; there is no migration that can override a later choice.
- Launch-time only. Auto-Start is evaluated exactly once per app process, at a true app launch. Switching tabs, opening a browser view, returning from Settings, or foregrounding the app never triggers a start.
- App resume does not restart stopped components. Resume refreshes UI state and nothing else.
- Manual Stop remains authoritative. A Service or Gateway you stop by hand stays stopped until you start it again or relaunch the app. This is structural: no code path starts either component outside app launch and your own button.
- Simplified, RC1-based implementation. The Android Service now uses
START_NOT_STICKYand ignores an OS-initiated restart that carries no originating intent. Preferences live in one canonical Android store, written synchronously and acknowledged only from a post-commit readback, so Settings shows the preference and the live runtime as two separate facts. - No background watchdog, boot receiver change, crash-restart policy, resurrection loop, or battery-optimization system. Background and battery work remains deferred.
Android Gateway reliability
- Fixed false stale/foreign PID detection on Android. A live, launcher-spawned Gateway could be logged as
pid belongs to another process; ignoring stale pid file, and its valid PID file deleted, while it was serving traffic normally. psoutput is no longer treated as authoritative argv when it is insufficient. Ownership was proven by searchingpsoutput for thegatewaysubcommand. On Android the Gateway is executed aslibpicoclaw.soand that argument is not reported, so a bare executable name is now treated as an inconclusive read rather than as proof of a foreign process, and the health endpoint decides instead.- Launcher-spawned process ownership is recognized directly. If the launcher started the exact PID itself and that process is alive, it owns it, decided before
psis consulted. - Stale, foreign, and dead PID protection remains. A dead process still has its PID file removed, a decisively foreign PID is still rejected and cleaned up, and PID reuse cannot make an unrelated new process trusted. PID validation was not disabled or weakened into blind trust.
Preserved RC1 security
Everything below is carried forward from v0.2.0-rc1 unchanged; no authorization, authentication, binding, or privacy code was modified in this candidate.
- The Core Gateway on port 18790 stays loopback-only, unconditionally and structurally rather than by configuration.
- Password-authenticated Dashboard with a revocable server-side session store.
- Server-derived owner authorization on every surface; forged sender, session, or owner fields cannot become the effective identity.
- Telegram is owner-only and refuses to start without exactly one paired numeric owner.
- Credential redaction in logs. This candidate additionally redacts JSON credential fields,
key=valuecredential assignments,Bearertokens, andsk-API keys, which RC1 did not cover. - Public Mode provides authenticated LAN access to the Dashboard only, and is unchanged from RC1.
- Skills 8/8 and 17 tools at startup.
Validation
Physically validated on a real ARM64 Android device on 2026-08-30. That run covered fresh install, Service Auto-Start, Gateway Auto-Start, manual Service stop and start, the Gateway starting automatically after the Service, no immediate Service resurrection, internal PocketClaw chat, Core startup, Skills 8/8, Tools 17, Core bound only to 127.0.0.1:18790 and [::1]:18790, a working Dashboard, and no recurrence of the PID ownership false positive.
Automated on the final commit: flutter analyze clean with 134 Flutter tests passing; the complete Go suite green with go test -tags goolm,stdjson ./... and go vet -tags goolm,stdjson ./... both exiting 0; focused Gateway/PID, Auto-Start, Telegram, authentication, and Public Mode suites passing. The RC1-to-RC2 diff contains no credential literals, no wildcard authorization, and no new LAN exposure, and the shipped Core binaries contain zero developer paths.
Native payload provenance. The Core binaries are committed build inputs and were deliberately not rebuilt for this release, so this APK carries the exact libpicoclaw.so and libpicoclaw-web.so that were physically validated, byte for byte. The versionCode bump from 4 to 5 means the released APK file itself is not byte-identical to the tested one; the native payload is.
Artifacts
| File | SHA-256 |
|---|---|
PocketClaw-v0.2.0-rc2-arm64.apk |
1cdfb20fb4514a5f8f998101dd1dd053a3cef3d758db33ed656fa433bcfc7050 |
PocketClaw-v0.2.0-rc2.aab |
154f3e0fa9ea7f4ba0f27001afe50d21d4fe6a6d89d6f6edc2254a5964aa0d71 |
libpicoclaw.so (in APK) |
0bf50e618a5f3cb92205365e9eb46df6d72e2c72d7d900ed76bb725563ce09da |
libpicoclaw-web.so (in APK) |
d38f200df217b3b31e79d5bc0dfbe0a8393fc845341f37a3abb1273718b5e758 |
Package com.lord1egypt.pocketclaw, version 0.2.0 (code 5), ABI arm64-v8a, built from tag v0.2.0-rc2.
Limitations
- Release candidate, not a final production release, and not published to Google Play.
- Signed with a debug key, as
v0.2.0-rc1was. Install by sideloading; this is not a Play-distributable signature. - Production hardening is deferred: no Flutter/Dart obfuscation, R8/ProGuard hardening, symbol stripping, or anti-reverse-engineering protection.
- Roadmap features remain deferred: Managed Runtime, the Statistics/Runtime page, WhatsApp Self-Chat, Android Keystore migration for provider secrets, and background/battery optimization settings.
- An optional automatic restart of the Gateway when it stops unexpectedly is not part of Auto-Start and remains deferred to a reliability milestone.
- Validated on one ARM64 Android device. This is not a claim of universal device compatibility. The APK is arm64-only and will not run on other ABIs.
PocketClaw v0.2.0-rc1
Release candidate. This is not the final production release, and it is not published to Google Play.
PocketClaw is an Android host for a PicoClaw-based agent runtime. This candidate is the first build where owner authorization is server-derived on every surface, the Core gateway can no longer reach a LAN by any configuration path, and Public Mode applies live.
Security
- Owner authorization is server-derived. The internal realtime channel binds each inbound message to its authenticated connection and to a Core-owned owner principal. Forged sender, user, session, owner, or chat fields cannot become the effective identity, and a stale or permissive on-disk allowlist cannot widen access.
- Password-authenticated Dashboard with real sessions. Login issues a cryptographically random HttpOnly cookie backed by a revocable server-side session store, validated on every request. Logging out revokes the session server-side rather than only clearing the browser cookie. Sessions last 24 hours.
- The Core Gateway stays loopback-only. The managed gateway on port 18790 is pinned to loopback unconditionally and no longer inherits the launcher's bind host, so exposing the Dashboard cannot expose Core. LAN clients reach the agent only through the authenticated Dashboard proxy.
- Telegram is owner-only. Managed Bot pairing stores the numeric Telegram user ID, and the channel refuses to start without exactly one paired numeric owner. Onboarding fails closed on empty, wildcard, and username-only owners. A username is never a security identity, and an unauthorized sender reaches neither the agent nor a provider.
- Credentials fail closed. Credential generation aborts when the platform CSPRNG is unavailable instead of falling back to a predictable value. The Android host's Core credential is a per-installation random value in no-backup storage rather than a constant compiled into the app. Provider API keys are never exposed to the browser.
Public Mode and LAN access
- Turning Public Mode on or off now applies immediately. A Dashboard listener supervisor rebinds only port 18800 between loopback and wildcard while the Core process, session store, Telegram polling, and agent runtime keep running — no manual service restart.
- A failed bind rolls back to the previous listener, and the setting is saved only after the new bind succeeds, so the UI can never claim a mode the socket is not in.
- The LAN URL and QR code show a real address from an active Wi-Fi or Ethernet link. Cellular-only, link-local, and wildcard addresses are never offered as connect targets; when there is no LAN address, the UI says so instead of encoding an unreachable URL.
- Telegram keeps working across a Public Mode change.
Runtime, channels, and providers
- Skills 8/8 available and 17 tools loaded at startup.
- Telegram final-delivery reliability, including the fix for the stall that required a second message.
- Provider catalog improvements and Telegram Managed Bot onboarding.
- PocketClaw system identity for a fresh default assistant.
Logs and privacy
- Duplicate log delivery fixed, and the Web Logs viewport is stable with no jitter.
- Correct UTF-8 throughout, including Arabic, emoji, and
µsdurations, in both the Logs view and exports. - Raw system prompts,
messages_json,tools_json, and raw reasoning are never dumped. Session keys are redacted, chat and sender IDs are internal, and Telegram payloads and credential fragments stay out of logs. - Internal paths display as
<internal>, and user-facing surfaces read as PocketClaw.
Verified
Physically validated on a real ARM64 Android device on 2026-08-29. That run covered startup, Skills 8/8, Tools 17, Telegram owner-only authorization and delivery, Web and realtime owner authorization, Dashboard password/session auth, Core staying loopback-only on 18790, Public Mode off and on with live off→on→off→on transitions without a service restart, a real 192.168.x.x:18800 LAN URL, authenticated Dashboard access from a computer on the same LAN, Core 18790 staying off the LAN, QR refresh, Web Logs stability, and the Unicode and privacy expectations above.
Automated: flutter analyze clean with 114/114 tests; frontend 46/46 with tsc -b and lint clean; the complete Go suite, build, and vet green.
Both Core binaries in this APK were reproduced byte for byte from the tagged source, so the shipped native payload is the payload that was physically validated.
Artifacts
| File | SHA-256 |
|---|---|
PocketClaw-v0.2.0-rc1-arm64.apk |
9bac23313a670d1f13474b65ceeac6f5d7aa55475f7c5c67eb613578d4540f91 |
PocketClaw-v0.2.0-rc1.aab |
5c1b97889404949cb3024729a9fbfdb47ac8561507f0f623dbff7dcf208e7f88 |
libpicoclaw.so (in APK) |
4e8c23c70bd77fbdce96d04004dd13b3ba4cac8e1e03164296cc47f7ead1ffb6 |
libpicoclaw-web.so (in APK) |
45427e0d48c53c7611625a8b621e4a4f565bfec11702d12e66c94ada2c900917 |
Package com.lord1egypt.pocketclaw, version 0.2.0 (code 4), ABI arm64-v8a, built from tag v0.2.0-rc1.
Limitations
- Release candidate, not a final production release, and not published to Google Play.
- Production hardening is deferred: no Flutter/Dart obfuscation, R8/ProGuard, symbol stripping, or anti-reverse-engineering protection in this build.
- Roadmap features are deferred: the Statistics/Runtime page, background and battery settings, service and gateway auto-start, a managed tool runtime, and Android Keystore migration for provider secrets.
- Validated on one ARM64 Android device. This is not a claim of universal device compatibility. The APK is arm64-only and will not run on other ABIs.