VPS vs running OpenClaw at home
OpenClaw only works while its gateway is running. On a laptop that sleeps, scheduled jobs are missed and messages go unanswered. A VPS is a small always-on computer you rent in a data center.
| VPS | Home computer or Mac mini | |
|---|---|---|
| Always on | Yes | Only if you never turn it off |
| Monthly cost | From about $5 for the server | Electricity only, after buying the hardware |
| Access to your local files and apps | No, it's a separate machine | Yes |
| iMessage | No, needs a Mac | Yes, on a Mac |
| Local AI models | Only on expensive GPU servers | Yes, on capable hardware |
| Isolation from your personal data | Strong | Depends on your setup |
Rule of thumb: choose a VPS if you mainly use chat apps, web tools and hosted models. Choose a home machine if you need your own files, iMessage or local models.
What size VPS does OpenClaw need?
Enough for one assistant using a hosted model and pre-built packages.
Comfortable room for browser automation, several channels and updates.
The official docs ask for at least 6 GB if you build the Docker image yourself.
Use Ubuntu 24.04 LTS or Debian 12, and add your SSH key when you create the server. Sizes above are our recommendations; local AI models need far more, usually a GPU.
Providers with official OpenClaw guides
- Hetzner
- DigitalOcean
- Hostinger
- Oracle Cloud
- Google Cloud
- Azure
- Fly.io
- Railway
- Render
See the provider list in the official VPS docs. Prices change often, so compare current plans before you buy.
Personalize the commands
Type your server's IP and the username you want. Every command below updates, ready to copy.
Connect and update the server
From your computer, log in as root and install the latest security updates.
apt-get update && apt-get upgrade -y
apt-get install -y curl git ufw unattended-upgradesCreate a user for OpenClaw
Don't run your assistant as root. If something goes wrong, a normal user limits the damage. Create one, give it your SSH key, then log in as that user.
Set up the firewall
Allow SSH and nothing else. OpenClaw's gateway listens on 127.0.0.1:18789, which is only reachable from the server itself. You will reach it through a tunnel, so do not open port 18789.
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status verboseIf your provider has its own firewall, allow only TCP port 22 from your own network. As the official docs put it, the firewall only needs to admit SSH, not port 18789.
Install OpenClaw
Logged in as your new user, run the official installer, then the onboarding wizard. The wizard asks for your model provider and API key.
curl -fsSL https://openclaw.ai/install.sh | bash
openclaw onboard --install-daemonThe --install-daemon flag installs the gateway as a systemd user service called openclaw-gateway.service.
Prefer containers? Follow our Docker guide instead. It needs Docker, Compose v2 and more RAM.
Keep it running after you log out
User services normally stop when you disconnect. Enable lingering so OpenClaw starts on boot and keeps running without an open SSH session.
loginctl enable-lingerCheck that the gateway is healthy:
openclaw gateway status
openclaw healthWatch the live logs if anything looks wrong:
journalctl --user -u openclaw-gateway.service -fopenclaw gateway startStartopenclaw gateway stopStopopenclaw gateway restartRestart after config changesopenclaw doctorDiagnose and repairOpen the Control UI securely
The dashboard runs on the server's loopback address. Choose one way to reach it from your computer.
Run this on your computer and leave it open. It forwards your local port 18789 to the server through your encrypted SSH connection.
Now open http://127.0.0.1:18789/ in your browser. If the tunnel is refused, make sure AllowTcpForwarding isn't disabled in /etc/ssh/sshd_config.
Install Tailscale on the server and your devices, then let OpenClaw publish the gateway inside your private tailnet with HTTPS. The gateway itself stays on loopback.
{
gateway: {
bind: "loopback",
tailscale: { mode: "serve" },
},
}Restart the gateway, then open https://<your-server>.<tailnet>.ts.net/ from any device on your tailnet. Don't use Tailscale Funnel, which makes the gateway public.
Connect a chat app
Telegram is the easiest channel on a VPS because it connects outward to Telegram with long polling. You don't need to open any ports.
{
channels: {
telegram: {
botToken: "PASTE_YOUR_BOT_TOKEN",
dmPolicy: "pairing",
},
},
}openclaw gateway restart
openclaw pairing list
openclaw pairing approve telegram <code>Then build your first automation with our first workflow tutorial. For other apps see WhatsApp, Slack and Discord.
Updates and backups
Update OpenClaw
openclaw update
openclaw gateway restartAutomatic security patches
sudo dpkg-reconfigure -plow unattended-upgradesBack up your assistant
Everything that makes your assistant yours lives in ~/.openclaw: config, memory, skills and workspace. Copy it to your computer regularly:
tar -czf ~/openclaw-backup-$(date +%F).tar.gz -C ~ .openclawThe backup contains tokens and API keys. Store it somewhere private and encrypted. Also turn on your provider's server snapshots. More in our update and backup guide.
A public server needs extra care
Your VPS is on the internet from the moment it starts. Tick these off before connecting personal accounts.
Read the full OpenClaw security guide.
VPS hosting questions
How much does it cost to host OpenClaw on a VPS?
A small VPS suitable for OpenClaw typically starts at around $5 a month, and the OpenClaw software is free. Your AI model usage is billed separately by your model provider.
What are the minimum VPS requirements for OpenClaw?
For one assistant using a hosted model, 1 to 2 vCPUs and 2 GB of RAM can work. We recommend 2 vCPUs, 4 GB of RAM and 40 GB of storage. Building the Docker image yourself needs at least 6 GB of RAM.
Should I open port 18789 on my VPS?
No. Keep the gateway bound to loopback and reach it through an SSH tunnel or Tailscale Serve. The official docs say your firewall only needs to allow SSH.
Why does OpenClaw stop when I log out of SSH?
The gateway runs as a systemd user service. Run loginctl enable-linger so it keeps running after you disconnect and starts again after a reboot.
Can I use WhatsApp with OpenClaw on a VPS?
Yes. Pair it by following the WhatsApp channel guide from the Control UI through your SSH tunnel. iMessage is the exception, because it requires a Mac.
Which is better for OpenClaw, a VPS or a Mac mini?
A VPS is cheaper to start, always on and isolated from your personal data. A Mac mini at home can use iMessage, your local files and local AI models. Many people use a VPS for chat and scheduling and keep sensitive work at home.