How to Host OpenClaw on a VPS

Run OpenClaw 24/7 on a small cloud server so your assistant answers and runs scheduled jobs even when your laptop is closed. This guide sets up a secure Ubuntu server step by step, with no ports exposed to the internet.

  • Timeabout 45 minutes
  • LevelIntermediate
  • Server costfrom about $5/month
Why a VPS

VPS vs running OpenClaw at home

OpenClaw only works while its gateway is running. On a laptop that sleeps, scheduled jobs are missed and messages go unanswered. A VPS is a small always-on computer you rent in a data center.

VPSHome computer or Mac mini
Always onYesOnly if you never turn it off
Monthly costFrom about $5 for the serverElectricity only, after buying the hardware
Access to your local files and appsNo, it's a separate machineYes
iMessageNo, needs a MacYes, on a Mac
Local AI modelsOnly on expensive GPU serversYes, on capable hardware
Isolation from your personal dataStrongDepends on your setup

Rule of thumb: choose a VPS if you mainly use chat apps, web tools and hosted models. Choose a home machine if you need your own files, iMessage or local models.

Choose a server

What size VPS does OpenClaw need?

Minimum1–2 vCPU · 2 GB RAM

Enough for one assistant using a hosted model and pre-built packages.

Recommended2 vCPU · 4 GB RAM · 40 GB SSD

Comfortable room for browser automation, several channels and updates.

Docker build6 GB+ RAM

The official docs ask for at least 6 GB if you build the Docker image yourself.

Use Ubuntu 24.04 LTS or Debian 12, and add your SSH key when you create the server. Sizes above are our recommendations; local AI models need far more, usually a GPU.

Providers with official OpenClaw guides

  • Hetzner
  • DigitalOcean
  • Hostinger
  • Oracle Cloud
  • Google Cloud
  • Azure
  • Fly.io
  • Railway
  • Render

See the provider list in the official VPS docs. Prices change often, so compare current plans before you buy.

Make it yours

Personalize the commands

Type your server's IP and the username you want. Every command below updates, ready to copy.

1
Step 1

Connect and update the server

From your computer, log in as root and install the latest security updates.

Your computer
Server
apt-get update && apt-get upgrade -y
apt-get install -y curl git ufw unattended-upgrades
2
Step 2

Create a user for OpenClaw

Don't run your assistant as root. If something goes wrong, a normal user limits the damage. Create one, give it your SSH key, then log in as that user.

Server (as root)
Your computer
3
Step 3

Set up the firewall

Allow SSH and nothing else. OpenClaw's gateway listens on 127.0.0.1:18789, which is only reachable from the server itself. You will reach it through a tunnel, so do not open port 18789.

Server
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status verbose
Using a cloud firewall too?

If your provider has its own firewall, allow only TCP port 22 from your own network. As the official docs put it, the firewall only needs to admit SSH, not port 18789.

4
Step 4

Install OpenClaw

Logged in as your new user, run the official installer, then the onboarding wizard. The wizard asks for your model provider and API key.

Server
curl -fsSL https://openclaw.ai/install.sh | bash
openclaw onboard --install-daemon

The --install-daemon flag installs the gateway as a systemd user service called openclaw-gateway.service.

Prefer containers? Follow our Docker guide instead. It needs Docker, Compose v2 and more RAM.

5
Step 5

Keep it running after you log out

User services normally stop when you disconnect. Enable lingering so OpenClaw starts on boot and keeps running without an open SSH session.

Server
loginctl enable-linger

Check that the gateway is healthy:

Server
openclaw gateway status
openclaw health

Watch the live logs if anything looks wrong:

Server
journalctl --user -u openclaw-gateway.service -f
openclaw gateway startStart
openclaw gateway stopStop
openclaw gateway restartRestart after config changes
openclaw doctorDiagnose and repair
6
Step 6

Open the Control UI securely

The dashboard runs on the server's loopback address. Choose one way to reach it from your computer.

Run this on your computer and leave it open. It forwards your local port 18789 to the server through your encrypted SSH connection.

Your computer

Now open http://127.0.0.1:18789/ in your browser. If the tunnel is refused, make sure AllowTcpForwarding isn't disabled in /etc/ssh/sshd_config.

7
Step 7

Connect a chat app

Telegram is the easiest channel on a VPS because it connects outward to Telegram with long polling. You don't need to open any ports.

~/.openclaw/openclaw.json (JSON5)
{
  channels: {
    telegram: {
      botToken: "PASTE_YOUR_BOT_TOKEN",
      dmPolicy: "pairing",
    },
  },
}
Server
openclaw gateway restart
openclaw pairing list
openclaw pairing approve telegram <code>

Then build your first automation with our first workflow tutorial. For other apps see WhatsApp, Slack and Discord.

Maintenance

Updates and backups

Update OpenClaw

Server
openclaw update
openclaw gateway restart

Automatic security patches

Server
sudo dpkg-reconfigure -plow unattended-upgrades

Back up your assistant

Everything that makes your assistant yours lives in ~/.openclaw: config, memory, skills and workspace. Copy it to your computer regularly:

Server
tar -czf ~/openclaw-backup-$(date +%F).tar.gz -C ~ .openclaw
Your computer

The backup contains tokens and API keys. Store it somewhere private and encrypted. Also turn on your provider's server snapshots. More in our update and backup guide.

Security checklist

A public server needs extra care

Your VPS is on the internet from the moment it starts. Tick these off before connecting personal accounts.

Read the full OpenClaw security guide.

FAQ

VPS hosting questions

How much does it cost to host OpenClaw on a VPS?

A small VPS suitable for OpenClaw typically starts at around $5 a month, and the OpenClaw software is free. Your AI model usage is billed separately by your model provider.

What are the minimum VPS requirements for OpenClaw?

For one assistant using a hosted model, 1 to 2 vCPUs and 2 GB of RAM can work. We recommend 2 vCPUs, 4 GB of RAM and 40 GB of storage. Building the Docker image yourself needs at least 6 GB of RAM.

Should I open port 18789 on my VPS?

No. Keep the gateway bound to loopback and reach it through an SSH tunnel or Tailscale Serve. The official docs say your firewall only needs to allow SSH.

Why does OpenClaw stop when I log out of SSH?

The gateway runs as a systemd user service. Run loginctl enable-linger so it keeps running after you disconnect and starts again after a reboot.

Can I use WhatsApp with OpenClaw on a VPS?

Yes. Pair it by following the WhatsApp channel guide from the Control UI through your SSH tunnel. iMessage is the exception, because it requires a Mac.

Which is better for OpenClaw, a VPS or a Mac mini?

A VPS is cheaper to start, always on and isolated from your personal data. A Mac mini at home can use iMessage, your local files and local AI models. Many people use a VPS for chat and scheduling and keep sensitive work at home.

Keep reading