# carapace

> A secure, stable Rust alternative to openclaw/moltbot/clawdbot

- **URL**: https://www.freshcrate.ai/projects/carapace
- **Author**: puremachinery
- **Category**: Security
- **Latest version**: `v0.8.0` (2026-05-01)
- **License**: Apache-2.0
- **Source**: https://github.com/puremachinery/carapace
- **Homepage**: https://getcara.io/
- **Language**: Rust
- **GitHub**: 43 stars, 6 forks
- **Registry**: github
- **Tags**: `ai-assistant`, `anthropic`, `chatbot`, `discord-bot`, `gemini`, `llm`, `llm-agent`, `local-first`, `rust`

## Description

A secure, stable Rust alternative to openclaw/moltbot/clawdbot

## Recent releases

| Version | Date | Urgency | Changes |
| --- | --- | --- | --- |
| `v0.8.0` | 2026-05-01 | High | ## Summary  - Provider setup and runtime routing now require explicit `provider:model`   IDs across config, request bodies, and WebSocket surfaces; bare and   slash-form model strings are rejected. - Provider coverage extends to Codex subscription-login, Vertex AI, Bedrock,   Venice AI, and the local Claude CLI alongside Anthropic, OpenAI, Gemini,   and Ollama. - WebSocket and HTTP configuration/model errors expose public-safe messages   and typed error codes while logging operator hints server- |
| `v0.7.0` | 2026-04-13 | High | ## Summary - Added encrypted session artifacts at rest, including `.crypto-manifest` recovery metadata, stricter integrity handling, and fail-closed recovery behavior for encrypted session state. - Added named execution routes plus session-level route precedence so requests, sessions, agents, and defaults can target reusable backend definitions instead of repeating raw `provider:model` strings everywhere. - Unified shared OAuth onboarding and auth-profile persistence for Codex and Gemini flows, |
| `v0.6.0` | 2026-04-06 | High | ## Summary - Added guided onboarding and Control UI onboarding/status support for more provider paths, including Anthropic setup-token auth profiles, Bedrock validation, and Vertex setup guidance. - Standardized model routing on explicit `provider:model` syntax and expanded Vertex AI support to Anthropic, Meta, Mistral, and Nvidia third-party publishers via `streamRawPredict`. - Added migration/import flows for OpenClaw, OpenCode, Aider, and NemoClaw so existing provider configuration can be bro |
| `v0.5.0` | 2026-03-30 | Medium | ## Summary - Added a per-channel activity framework for typing indicators and explicit after-response read receipts. - Enabled Signal typing indicators and explicit after-response read receipts behind `channels.*.features.*` policy controls, with bounded ownership, retry, and shutdown semantics. - Refreshed release-facing docs, capability/status inventories, and the Signal smoke playbook to match the shipped channel-activity surface.  ## Breaking Changes - None.  ## Migration Steps - No manual m |
| `v0.4.1` | 2026-03-24 | Medium | ## Summary - Hardened `cara plugins install\|update --file` so local managed plugin staging rolls back cleanly on failure and surfaces clearer recovery guidance. - Improved `plugins.status` reporting when plugin loader initialization fails early so managed plugins still appear with per-plugin failure rows. - Tightened release and CI ergonomics with a fixed guarded `nextest` watchdog parser and explicit fast/golden/integration/full test lanes.  ## Breaking Changes - None.  ## Migration Steps - No |
| `v0.4.0` | 2026-03-23 | Medium | ## Summary - Strengthened `cara setup` with structured verification, clearer remediation, and concrete next-step guidance. - Shipped the first stable WASM plugin runtime, including managed plugin activation, runtime reporting, and public plugin development docs. - Standardized the extension surface on `plugins.*` and added `cara plugins` commands for status, install, update, and managed binary inspection. - Refreshed plugin/runtime test coverage and dependency baselines, including current `wasmt |
| `v0.3.0` | 2026-03-19 | Low | ## Summary - Added Codex subscription-login onboarding as a first-class provider path. - Hardened the OpenAI-compatible runtime path and improved compatibility handling. - Fixed two user-facing protocol bugs: Gemini thought-signature replay on newer thinking models and Signal duplicate-field payload parsing. - Refreshed docs and release surfaces to match the current stable line.  ## Breaking Changes - None.  ## Migration Steps - No manual migration is required for the stable path from `v0.2.x` t |
| `v0.2.0` | 2026-03-13 | Low | ## What's Changed * build(deps): bump aws-lc-fips-sys from 0.13.11 to 0.13.12 by @dependabot[bot] in https://github.com/puremachinery/carapace/pull/124 * ci(claude): fix missing review publish by allowing Write by @puremachinery in https://github.com/puremachinery/carapace/pull/126 * test(cli): add scripted interactive setup harness coverage by @puremachinery in https://github.com/puremachinery/carapace/pull/125 * ci(test): root-cause diagnostics for nextest discovery stalls by @puremachinery in |
| `v0.1.0` | 2026-03-03 | Low | ## What's Changed * ci: align claude review trigger coverage with taisr by @puremachinery in https://github.com/puremachinery/carapace/pull/108 * chore: make pre-commit rust checks conditional and progress-visible by @puremachinery in https://github.com/puremachinery/carapace/pull/109 * build(deps): bump the github-actions-minor-patch group with 2 updates by @dependabot[bot] in https://github.com/puremachinery/carapace/pull/113 * build(deps): bump the cargo-minor-patch group with 3 updates by @d |
| `v0.1.0-preview12` | 2026-02-26 | Low | ## Highlights  This release includes everything that landed after `v0.1.0-preview10`.  ### Long-running assistant execution - Added a durable objective task queue with crash-safe persistence and startup recovery. - Added operator controls for tasks: cancel, retry, resume, patch, and policy-aware transitions. - Added continuation budgets (attempts, total runtime, per-run timeout, max turns) with enforcement. - Wired `/hooks/wake` and hook-mapping agent actions to real dispatch paths. - Added dete |

## Citation

- HTML: https://www.freshcrate.ai/projects/carapace
- Markdown: https://www.freshcrate.ai/projects/carapace.md
- Dependencies JSON: https://www.freshcrate.ai/api/projects/carapace/deps

_Generated by freshcrate.ai. Indexes github releases for AI-agent ecosystem packages._
