DYNAM Windows Companion: Windows tray, chat, and PC connection built on OpenClaw Windows Node.
C#
0
1,290 commits
updated Oct 2, 2026

Windows tray, native agent chat and PC capabilities for DYNAM client runtimes. Derived from OpenClaw Windows Node v2026.9.4 under its retained MIT license.
DYNAM Windows Companion is the required default Windows companion for new DYNAM client deployments. Rollout is gated on signed artifacts and tenant-specific native enrollment proof. Current policy is in deployment/windows-companion-policy.json. No production installer is claimed available until a signed release exists.
The branded build preserves existing connection data and internal installation identifiers. Upstream reference documentation below still describes the underlying OpenClaw protocol and capabilities. Client connection codes belong only in private, short-lived enrollment delivery, never in this public repository.
Go to Settings → Apps → Installed apps, find DYNAM Windows Companion, and click Uninstall (or use Add or Remove Programs in Control Panel). You'll be asked whether to also remove the local WSL gateway; choose Yes to unregister its WSL distro and generated state, or No to leave the gateway and that state in place.
Your settings file at %APPDATA%\OpenClawTray\settings.json is not removed automatically, and device identity files for gateways unrelated to the one you removed are preserved. Choosing Yes also removes the removed gateway's own identity directory under %APPDATA%\OpenClawTray\gateways\. Root operator and node tokens are preserved only while an external gateway record remains; otherwise they are cleared, even if another local or loopback gateway record remains. Delete %APPDATA%\OpenClawTray\ manually for a fully clean uninstall. See docs/SETUP.md for details, including the headless --uninstall --confirm-destructive CLI path used for testing.
Use DYNAM Windows Companion for normal setup. You should not need to edit openclaw.json by hand.
Node mode registers this PC as a node and advertises only the capabilities enabled in Permissions. Gateway policy and local Windows checks can still block a capability.
| Capability | What it lets agents do |
|---|---|
| System tools | Run shell commands and scripts, subject to local exec approvals and sandbox policy |
| Browser control | Drive a compatible Chromium browser on this PC |
| Camera | Capture still images and short camera clips |
| Canvas | Present and interact with visual content in a hosted window |
| Screen capture | Take screenshots and short screen recordings |
| Location | Read this PC's approximate location |
| Text-to-speech | Speak text aloud through this PC's speakers |
| Speech-to-text | Transcribe microphone audio locally |
Notifications and basic device status are available when Node mode is active. Windows may request consent before camera, microphone, location, or screen features can run.
Privacy-sensitive capabilities should stay off unless you intend to use them. This includes camera capture, screen recording, microphone transcription, spoken output, and command execution.
OpenClaw applies more than one trust check:
After changing gateway command policy, approve any pending-reapproval request shown by the app and reconnect the node. The app never silently opts into privacy-sensitive gateway commands.
Use your gateway's supported configuration tools when OpenClaw Companion cannot manage that gateway. Preserve existing entries and add only the exact commands you need. Wildcards such as canvas.* are not expanded.
{
"gateway": {
"nodes": {
"allowCommands": [
"system.notify",
"canvas.present",
"canvas.hide",
"screen.snapshot",
"device.info",
"device.status"
]
}
}
}
Canonical paired Windows nodes already receive the desktop system.* defaults,
including system.run, system.run.prepare, and system.which. Windows still
applies the local Run system tools switch, V2 exec approvals, and sandbox
policy. Commands outside the Windows gateway defaults, including
screen.record, camera.snap, camera.clip, stt.transcribe, and
tts.speak, require deliberate gateway opt-in. Reapprove and reconnect the
node after changing the effective command set.
Share Windows Ollama in the Permissions page is a separate opt-in. It
advertises ollama.models and ollama.chat so the active paired gateway,
whether local or remote, can use an Ollama service running on Windows loopback.
It does not change or reuse the app-managed Local AI gateway provider. Older
gateways require both exact Ollama commands in gateway.nodes.allowCommands;
newer gateways with the bundled Ollama plugin can expose them through the
node_inference agent tool.
See Operator and node concepts for the pairing and trust model, and Windows node testing for command-level reference material.
The Sandbox page controls programs launched through the Windows node's system.run capability:
When enabled and available, the Windows node uses MXC process isolation for system.run. If MXC is unavailable and strict fallback blocking is off, OpenClaw can fall back to uncontained host execution for compatibility. The Sandbox page shows the current state and lets you choose the appropriate policy.
This sandbox covers commands run through the Windows node. Commands run directly on the gateway use the gateway's separate security controls.
Ctrl+Alt+Shift+C global hotkeyopenclaw:// deep links for automation| Link | Action |
|---|---|
openclaw://settings | Open Companion Settings |
openclaw://setup | Open the setup wizard |
openclaw://chat | Open Chat |
openclaw://commandcenter | Open Command Center |
openclaw://send?message=Hello | Open Quick Send with pre-filled text |
openclaw://logs | Open the current log file |
openclaw://support-context | Copy redacted support context |
openclaw://capability-diagnostics | Copy capability and allowlist diagnostics |
Deep links are forwarded through IPC when OpenClaw Companion is already running.
| Data | Default path |
|---|---|
| App settings | %APPDATA%\OpenClawTray\settings.json |
| Gateway registry | %APPDATA%\OpenClawTray\gateways.json |
| Logs | %LOCALAPPDATA%\OpenClawTray\openclaw-tray.log |
| Exec approvals | %APPDATA%\OpenClawTray\exec-approvals.json |
The default local gateway URL is ws://localhost:18789.
| Project | Purpose |
|---|---|
| OpenClaw.Tray.WinUI | WinUI 3 tray app and Companion Settings |
| OpenClaw.Connection | Gateway registry, credential resolution, and connection manager |
| OpenClaw.Shared | Gateway client, Windows capabilities, diagnostics, and MCP bridge |
| OpenClaw.Chat | Native chat model and timeline reducer |
| OpenClaw.WinNode.Cli | winnode CLI for local Windows node and MCP invocation |
| OpenClaw.SetupEngine | WSL gateway installation and setup-code pairing |
| OpenClaw.SetupEngine.UI | WinUI setup wizard pages |
| OpenClaw.Cli | Gateway WebSocket validation CLI |
| OpenClawTray.FunctionalUI | Declarative WinUI helpers used by newer surfaces |
.\scripts\setup-dev.ps1
.\scripts\setup-dev.ps1 -CheckOnly
.\scripts\setup-dev.ps1 -RunValidation
.\build.ps1
.\build.ps1 -Project WinUI
.\build.ps1 -CheckOnly
Direct WinUI builds require a runtime identifier:
dotnet build .\src\OpenClaw.Tray.WinUI\OpenClaw.Tray.WinUI.csproj -r win-x64
dotnet build .\src\OpenClaw.Tray.WinUI\OpenClaw.Tray.WinUI.csproj -r win-arm64
dotnet build .\src\OpenClaw.Tray.WinUI\OpenClaw.Tray.WinUI.csproj -r win-x64 -p:PackageMsix=true
run-app-local.ps1 allows main by default. Pass -AllowNonMain when previewing a feature branch or linked worktree.
.\run-app-local.ps1
.\run-app-local.ps1 -NoBuild
.\run-app-local.ps1 -AllowNonMain -Isolated
.\run-app-local.ps1 -AllowNonMain -Dev -Isolated
.\run-app-local.ps1 -AllowNonMain -Configuration Release -Isolated -UpdateChannel alpha
Set the repository root explicitly so tests also work in linked worktrees:
$env:OPENCLAW_REPO_ROOT = (Get-Location).Path
dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj
dotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj
These commands restore and build the test projects when needed. Use --no-restore only after each test project has built successfully in the current worktree.
| Topic | Document |
|---|---|
| Architecture ownership | docs/ARCHITECTURE.md |
| Audio model asset integrity | docs/AUDIO_MODEL_ASSETS.md |
| Connection and pairing | docs/CONNECTION_ARCHITECTURE.md |
| Gateway, node, and exec flow FAQ | docs/OPENCLAW_GATEWAY_NODE_EXEC_FAQ.md |
| Onboarding wizard | docs/ONBOARDING_WIZARD.md |
| Windows node behavior | docs/WINDOWS_NODE_TESTING.md |
| Local MCP mode | docs/MCP_MODE.md |
| Managed WSL gateway | docs/WSL_GATEWAY_ADMIN.md |
| Development | DEVELOPMENT.md |
C#
93.2%
Python
3.5%
PowerShell
3.2%
DYNAM Windows Companion: Windows tray, chat, and PC connection built on OpenClaw Windows Node.
C#
0
1,290 commits
updated Oct 2, 2026

Windows tray, native agent chat and PC capabilities for DYNAM client runtimes. Derived from OpenClaw Windows Node v2026.9.4 under its retained MIT license.
DYNAM Windows Companion is the required default Windows companion for new DYNAM client deployments. Rollout is gated on signed artifacts and tenant-specific native enrollment proof. Current policy is in deployment/windows-companion-policy.json. No production installer is claimed available until a signed release exists.
The branded build preserves existing connection data and internal installation identifiers. Upstream reference documentation below still describes the underlying OpenClaw protocol and capabilities. Client connection codes belong only in private, short-lived enrollment delivery, never in this public repository.
Go to Settings → Apps → Installed apps, find DYNAM Windows Companion, and click Uninstall (or use Add or Remove Programs in Control Panel). You'll be asked whether to also remove the local WSL gateway; choose Yes to unregister its WSL distro and generated state, or No to leave the gateway and that state in place.
Your settings file at %APPDATA%\OpenClawTray\settings.json is not removed automatically, and device identity files for gateways unrelated to the one you removed are preserved. Choosing Yes also removes the removed gateway's own identity directory under %APPDATA%\OpenClawTray\gateways\. Root operator and node tokens are preserved only while an external gateway record remains; otherwise they are cleared, even if another local or loopback gateway record remains. Delete %APPDATA%\OpenClawTray\ manually for a fully clean uninstall. See docs/SETUP.md for details, including the headless --uninstall --confirm-destructive CLI path used for testing.
Use DYNAM Windows Companion for normal setup. You should not need to edit openclaw.json by hand.
Node mode registers this PC as a node and advertises only the capabilities enabled in Permissions. Gateway policy and local Windows checks can still block a capability.
| Capability | What it lets agents do |
|---|---|
| System tools | Run shell commands and scripts, subject to local exec approvals and sandbox policy |
| Browser control | Drive a compatible Chromium browser on this PC |
| Camera | Capture still images and short camera clips |
| Canvas | Present and interact with visual content in a hosted window |
| Screen capture | Take screenshots and short screen recordings |
| Location | Read this PC's approximate location |
| Text-to-speech | Speak text aloud through this PC's speakers |
| Speech-to-text | Transcribe microphone audio locally |
Notifications and basic device status are available when Node mode is active. Windows may request consent before camera, microphone, location, or screen features can run.
Privacy-sensitive capabilities should stay off unless you intend to use them. This includes camera capture, screen recording, microphone transcription, spoken output, and command execution.
OpenClaw applies more than one trust check:
After changing gateway command policy, approve any pending-reapproval request shown by the app and reconnect the node. The app never silently opts into privacy-sensitive gateway commands.
Use your gateway's supported configuration tools when OpenClaw Companion cannot manage that gateway. Preserve existing entries and add only the exact commands you need. Wildcards such as canvas.* are not expanded.
{
"gateway": {
"nodes": {
"allowCommands": [
"system.notify",
"canvas.present",
"canvas.hide",
"screen.snapshot",
"device.info",
"device.status"
]
}
}
}
Canonical paired Windows nodes already receive the desktop system.* defaults,
including system.run, system.run.prepare, and system.which. Windows still
applies the local Run system tools switch, V2 exec approvals, and sandbox
policy. Commands outside the Windows gateway defaults, including
screen.record, camera.snap, camera.clip, stt.transcribe, and
tts.speak, require deliberate gateway opt-in. Reapprove and reconnect the
node after changing the effective command set.
Share Windows Ollama in the Permissions page is a separate opt-in. It
advertises ollama.models and ollama.chat so the active paired gateway,
whether local or remote, can use an Ollama service running on Windows loopback.
It does not change or reuse the app-managed Local AI gateway provider. Older
gateways require both exact Ollama commands in gateway.nodes.allowCommands;
newer gateways with the bundled Ollama plugin can expose them through the
node_inference agent tool.
See Operator and node concepts for the pairing and trust model, and Windows node testing for command-level reference material.
The Sandbox page controls programs launched through the Windows node's system.run capability:
When enabled and available, the Windows node uses MXC process isolation for system.run. If MXC is unavailable and strict fallback blocking is off, OpenClaw can fall back to uncontained host execution for compatibility. The Sandbox page shows the current state and lets you choose the appropriate policy.
This sandbox covers commands run through the Windows node. Commands run directly on the gateway use the gateway's separate security controls.
Ctrl+Alt+Shift+C global hotkeyopenclaw:// deep links for automation| Link | Action |
|---|---|
openclaw://settings | Open Companion Settings |
openclaw://setup | Open the setup wizard |
openclaw://chat | Open Chat |
openclaw://commandcenter | Open Command Center |
openclaw://send?message=Hello | Open Quick Send with pre-filled text |
openclaw://logs | Open the current log file |
openclaw://support-context | Copy redacted support context |
openclaw://capability-diagnostics | Copy capability and allowlist diagnostics |
Deep links are forwarded through IPC when OpenClaw Companion is already running.
| Data | Default path |
|---|---|
| App settings | %APPDATA%\OpenClawTray\settings.json |
| Gateway registry | %APPDATA%\OpenClawTray\gateways.json |
| Logs | %LOCALAPPDATA%\OpenClawTray\openclaw-tray.log |
| Exec approvals | %APPDATA%\OpenClawTray\exec-approvals.json |
The default local gateway URL is ws://localhost:18789.
| Project | Purpose |
|---|---|
| OpenClaw.Tray.WinUI | WinUI 3 tray app and Companion Settings |
| OpenClaw.Connection | Gateway registry, credential resolution, and connection manager |
| OpenClaw.Shared | Gateway client, Windows capabilities, diagnostics, and MCP bridge |
| OpenClaw.Chat | Native chat model and timeline reducer |
| OpenClaw.WinNode.Cli | winnode CLI for local Windows node and MCP invocation |
| OpenClaw.SetupEngine | WSL gateway installation and setup-code pairing |
| OpenClaw.SetupEngine.UI | WinUI setup wizard pages |
| OpenClaw.Cli | Gateway WebSocket validation CLI |
| OpenClawTray.FunctionalUI | Declarative WinUI helpers used by newer surfaces |
.\scripts\setup-dev.ps1
.\scripts\setup-dev.ps1 -CheckOnly
.\scripts\setup-dev.ps1 -RunValidation
.\build.ps1
.\build.ps1 -Project WinUI
.\build.ps1 -CheckOnly
Direct WinUI builds require a runtime identifier:
dotnet build .\src\OpenClaw.Tray.WinUI\OpenClaw.Tray.WinUI.csproj -r win-x64
dotnet build .\src\OpenClaw.Tray.WinUI\OpenClaw.Tray.WinUI.csproj -r win-arm64
dotnet build .\src\OpenClaw.Tray.WinUI\OpenClaw.Tray.WinUI.csproj -r win-x64 -p:PackageMsix=true
run-app-local.ps1 allows main by default. Pass -AllowNonMain when previewing a feature branch or linked worktree.
.\run-app-local.ps1
.\run-app-local.ps1 -NoBuild
.\run-app-local.ps1 -AllowNonMain -Isolated
.\run-app-local.ps1 -AllowNonMain -Dev -Isolated
.\run-app-local.ps1 -AllowNonMain -Configuration Release -Isolated -UpdateChannel alpha
Set the repository root explicitly so tests also work in linked worktrees:
$env:OPENCLAW_REPO_ROOT = (Get-Location).Path
dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj
dotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj
These commands restore and build the test projects when needed. Use --no-restore only after each test project has built successfully in the current worktree.
| Topic | Document |
|---|---|
| Architecture ownership | docs/ARCHITECTURE.md |
| Audio model asset integrity | docs/AUDIO_MODEL_ASSETS.md |
| Connection and pairing | docs/CONNECTION_ARCHITECTURE.md |
| Gateway, node, and exec flow FAQ | docs/OPENCLAW_GATEWAY_NODE_EXEC_FAQ.md |
| Onboarding wizard | docs/ONBOARDING_WIZARD.md |
| Windows node behavior | docs/WINDOWS_NODE_TESTING.md |
| Local MCP mode | docs/MCP_MODE.md |
| Managed WSL gateway | docs/WSL_GATEWAY_ADMIN.md |
| Development | DEVELOPMENT.md |
C#
93.2%
Python
3.5%
PowerShell
3.2%