OpenClaw 2.0 puts the spotlight on verifiable authorization for autonomous agents
OpenClaw released version 2.0 on Aug. 30, describing it as the largest update in its history, with more than 16,000 pull requests spanning installation, messaging, memory, Skills, models, Automations, browser control, native apps, Plugins, and security. The release has renewed attention on a broader shift in the agent stack: AI agents are no longer limited to generating text and are gaining the ability to act on external systems.
That shift creates a trust problem that existing permission models struggle to handle. Full delegation, such as handing over a private key or a long-lived Session Key, can maximize automation but concentrates risk if prompt injection, malicious webpages, environmental contamination, or model misunderstanding leads to unintended actions. At the other extreme, requiring approval for every step protects users but strips much of the value from automation.
The article argues that the industry now needs finer-grained, verifiable authorization. It points to imToken’s exploration of Sigil, which aims to separate tool access from approval for a specific action. The proposed framework centers on clear, parameter-bound consent under the principle of "What you see is what you sign," using mechanisms such as Passkey, biometrics, one-time signatures, short validity windows, and request binding to ensure that what the user approved matches what the system actually executes.