OpenClaw Self-Hosted

IntermediateAi Agents

A personal AI agent on your own always-on server, reached through the chat apps you already use.

Published 2 October 2026

Core Tools
Docker
Docker
OpenClaw
OpenClaw
LLM
Claude
OpenAI
DeepSeek
GLM
MiniMax
Hosting
Hetzner
Hostinger
DigitalOcean
Fly.io
Raspberry Pi

About OpenClaw Self-Hosted

OpenClaw is an open-source personal AI agent, and the project behind it sells no subscription and runs no hosted service, so using it means running it somewhere. This stack runs it in Docker on a small server that stays on around the clock, which is what lets the agent act while you are away: answer a message at night, run a scheduled task, or finish a job it started hours ago. You talk to it through the messaging apps you already use, such as Telegram, WhatsApp, Slack, Discord, or Signal, and it works from the server with its own memory, files, and tools.

The official Docker setup starts one long-running service, the Gateway, and a second container for the command line. There is no database to operate. Configuration, credentials, and session state are SQLite files, the agent's memory is plain Markdown in its workspace, and all of it sits in one folder mounted from the host. The project's pre-built image avoids building from source, the only step that needs a large server. OpenClaw's installer script is the other official route, and it runs the same Gateway directly on the host without Docker.

Nothing has to be opened to the internet. The agent connects out to the messaging services, and the Gateway's dashboard listens only on the server's loopback address, so by default there is no reverse proxy to configure and no TLS certificate to renew. You reach the dashboard through an SSH tunnel. Tailscale can be added for private access from a phone or laptop, and Cloudflare Tunnel when a public address behind a login is needed. Putting the dashboard on your own domain is optional as well: a reverse proxy such as Caddy does it once a sign-in sits in front, and a self-hosted PaaS deploys the agent from a one-click template with HTTPS included. A container platform is the exception: it publishes the dashboard at its own HTTPS address unless you deploy it privately.

The model is a separate choice, and it is where the running cost sits. Claude is the default, and OpenAI, DeepSeek, GLM, or MiniMax is set during onboarding, with an API key or, for most of them, on a flat plan in place of per-token billing. The agent can run shell commands, read files, and browse on the machine it lives on, so a dedicated server is also a safety boundary: it keeps the agent away from your personal computer, and its tools can be confined to a Docker sandbox. Optional extras are a model gateway such as OpenRouter or LiteLLM, and a local model through Ollama or LM Studio on hardware strong enough to run one.

Key Features

  • ✓OpenClaw's Gateway in Docker, from the project's pre-built image, as one always-on service
  • ✓Reached through the chat apps you already use: Telegram, WhatsApp, Slack, Discord, Signal, and more
  • ✓No database to run: state is SQLite and Markdown files in one mounted folder
  • ✓Dashboard bound to loopback and reached over an SSH tunnel, with nothing open to the internet
  • ✓A model of your choice: Claude by default, or OpenAI, DeepSeek, GLM, or MiniMax, with fallbacks between them
  • ✓Unknown senders get a pairing code, not an answer, until you approve them
  • ✓A built-in backup command that archives configuration, credentials, and the agent's workspace

When to Use OpenClaw Self-Hosted

  • →A personal assistant you can message from your phone at any hour, without leaving a laptop running
  • →Scheduled and recurring work: morning briefings, reminders, watching a page or an inbox
  • →Keeping an agent that has shell and file access off your personal computer
  • →One assistant for a household or a small team in a shared group chat
  • →Running the agent on a low-cost or open-weight model without changing anything else

Pros

  • The software is free and MIT-licensed: you pay for a small server and for model usage
  • Conversations, memory, and credentials stay on a machine you control
  • Light enough for the smallest VPS plans or a single-board computer, because the model runs elsewhere
  • The model, the host, and the way you reach it each swap without touching the others

Cons

  • Updates, backups, and server security are yours, and the project releases often
  • An agent with shell access and your accounts is a real risk if a prompt injection gets through, and sandboxing is off by default
  • Model spend is hard to predict: an always-on agent with scheduled tasks uses tokens while you sleep
  • A headless server can't do what needs a desktop: iMessage needs a Mac, and browser automation runs without a visible window

LLM Options for OpenClaw Self-Hosted

Claude

OpenClaw Self-Hosted powered by Claude

The default. Claude keeps to long instructions across many tool calls, which is most of what a personal agent does. It connects in two ways: an API key billed per token, at $2 per million input tokens and $10 per million output on the current Sonnet model, or an existing Claude Code login on the same host, which draws on your Claude plan's limits. OpenClaw's docs advise the API key for anything shared or unattended, because its billing is the predictable one.

OpenAI

OpenClaw Self-Hosted powered by OpenAI

GPT models connect with an API key or by signing in with a ChatGPT or Codex plan, a route OpenClaw's docs describe as explicitly supported by OpenAI for external tools. That makes it a simple way to run the agent on a flat monthly plan. On the API, the mid-tier model costs $2 per million input tokens and $10 per million output, and the smallest tier, at $0.10 and $0.50, suits scheduled background tasks.

DeepSeek

OpenClaw Self-Hosted powered by DeepSeek

The low-cost API choice. OpenClaw's DeepSeek provider handles the model's reasoning mode across multi-step tool use, so nothing needs configuring beyond the key. The Flash model costs $0.15 per million input tokens and $0.60 per million output off-peak, with weekday peak hours billed at double, which keeps an agent that works all day to a few dollars a month. The API is run by a Chinese company, which rules it out under some data policies.

GLM

OpenClaw Self-Hosted powered by GLM

Z.ai's GLM models, most often used here through the GLM Coding Plan: a flat subscription from $18 a month with an allowance that resets every five hours and every week, which caps what an always-on agent can spend. OpenClaw's onboarding checks whether a key belongs to the Coding Plan or to the pay-as-you-go API and sets the matching endpoint. On the API, GLM-5.3 costs $1.40 per million input tokens and $4.40 per million output.

MiniMax

OpenClaw Self-Hosted powered by MiniMax

MiniMax-M3, either on a Token Plan from $22 a month with rolling five-hour and weekly quotas, or on the pay-as-you-go API at $0.30 per million input tokens and $1.20 per million output. With the plan, OpenClaw signs in through the browser and no API key is involved, and it shows the quota that is left the same way it does for other providers. The weights are open, so the same model can later move to a GPU server of your own.

These are highlighted picks. To see all the tools, check the LLM category.

Hosting Options for OpenClaw Self-Hosted

Hetzner

Deploy OpenClaw Self-Hosted on Hetzner

A plain root VPS, and the host that OpenClaw's own Docker guide is written for. A server with 4 GB of RAM costs around €5 to €6 a month, twice the recommended memory, which leaves room for browser automation and several channels. Use the pre-built image, since building it on the server needs 6 GB. The guide keeps the firewall closed to everything except SSH, and updates, backups, and hardening are yours.

Hostinger

Deploy OpenClaw Self-Hosted on Hostinger

The low-effort VPS. Hostinger has an OpenClaw template that deploys the Docker container for you, generates the gateway token, and puts logs, restarts, and updates behind buttons in its Docker Manager. The entry KVM 1 plan has 4 GB of RAM for $6.49 a month on a two-year term, renewing at $11.99. Prepaid AI credits can be bought at checkout, which skips getting a model API key. You keep root access, so the server is still yours to secure.

DigitalOcean

Deploy OpenClaw Self-Hosted on DigitalOcean

A cloud VPS billed per second up to a monthly cap. OpenClaw's DigitalOcean guide runs on the smallest regular Droplet, 1 vCPU and 1 GB of RAM for about $6 a month, with swap added to make it fit; the 2 GB Droplet at $12 matches the recommended memory. DigitalOcean also lists a 1-Click OpenClaw Droplet in its Marketplace, and OpenClaw's guide advises reviewing a marketplace image's startup scripts and firewall defaults before trusting one. Snapshots and a cloud firewall are in the control panel.

Fly.io

Deploy OpenClaw Self-Hosted on Fly.io

A container platform, so there is no server to patch or harden. OpenClaw's Fly.io guide deploys the same image as a Fly machine with a 1 GB volume for its state and recommends 2 GB of RAM, about $12 a month, billed per second. Unlike a VPS, the dashboard is published at a public HTTPS address by default, protected by the gateway token. The guide's private configuration removes the public address, and you then reach it through Fly's proxy or WireGuard.

Raspberry Pi

Deploy OpenClaw Self-Hosted on Raspberry Pi

Your own hardware, for the agent only. A Pi 4 or 5 with 2 GB of RAM or more runs the Gateway well, and OpenClaw's Pi guide installs it directly on 64-bit Raspberry Pi OS, without Docker. The model still runs at a provider: the guide says not to run local models on a Pi, because even small ones are too slow to be useful, so Ollama and LM Studio belong on a stronger machine. A Pi 5 with 4 GB costs about $110 once, plus a few dollars of electricity a month. Keep its state on a USB SSD and not on the SD card.

These are highlighted picks. To see all the tools, check the Hosting & Cloud category.

OpenClaw Self-Hosted Add-ons

Each addition below extends this stack with a capability the base stack works fine without. None are required: include the ones your product actually needs when building this stack, and skip the rest.

Model Inference Add-ons

Add model inference when you want an open-weight model in the mix: on your own hardware for privacy, or on a hosted inference provider for speed and low per-token prices.

Ollama

OpenClaw Self-Hosted with Ollama

Runs open-weight models and serves them to OpenClaw over Ollama's native API, which OpenClaw's docs require for tool calling to work. It suits a headless machine: it installs as a background service and pulls models by name. The model needs real hardware, a GPU or a recent Mac with plenty of memory, so it is not for a small VPS or a Raspberry Pi. The usual layout is the agent on the small server and Ollama on a stronger machine it can reach. Ollama's cloud models connect the same way when local hardware isn't enough.

LM Studio

OpenClaw Self-Hosted with LM Studio

The desktop route to a local model: a graphical app for downloading and loading models, with a local server that OpenClaw connects to on port 1234. It fits an agent on a home Mac or PC, or a desktop on the same network as the server. OpenClaw offers only the models that report tool support and at least 16K of context, and its docs advise the largest build your hardware can hold over small or heavily quantized ones. Free for personal and work use.

These are highlighted picks. To see all the tools, check the AI Runtime & Serving category.

Model Aggregator Add-ons

Add a model aggregator when you want one API key and one bill for models from many providers, with automatic fallback when one of them is down, instead of setting up each provider separately.

OpenRouter

OpenClaw Self-Hosted with OpenRouter

One key and one prepaid balance for hundreds of models, set up in OpenClaw's onboarding with an API key or a browser sign-in. Its auto route lets OpenRouter choose a model for each request. It is useful for finding out which model suits your agent before settling on one provider, and as a fallback when a provider is down. Models are billed at the providers' prices, with a 5.5% fee when you buy credits.

LiteLLM

OpenClaw Self-Hosted with LiteLLM

A gateway you host yourself, as one more container next to OpenClaw, which connects to it as a provider on port 4000. LiteLLM holds the real provider keys, and the agent only sees a virtual key with a spending limit. That is a useful brake on an agent that runs unattended: when the budget is used up, the calls stop. It also logs the cost of each request and fails over between backends. The open-source edition is free, and it needs a PostgreSQL database for keys and spend records.

These are highlighted picks. To see all the tools, check the AI Model Aggregators category.

Tunnel Add-ons

Add a tunnel when you're self-hosting without a static IP or can't open inbound ports — a home server, a VPS behind restrictive network policies, or anywhere a reverse proxy alone can't reach the internet.

Tailscale

OpenClaw Self-Hosted with Tailscale

The private route, and one OpenClaw integrates directly. With its Tailscale mode set to serve, the Gateway stays on loopback and the dashboard becomes an HTTPS address that only your own devices on the tailnet can open, so a phone reaches it with no SSH tunnel. Those devices can be recognised by their Tailscale identity in place of a token. Funnel mode publishes the dashboard to the internet and requires a password. The Personal plan is free.

Cloudflare Tunnel

OpenClaw Self-Hosted with Cloudflare Tunnel

For a stable public address with a login in front of it. OpenClaw documents the setup: cloudflared connects outbound from the server to the loopback Gateway, Cloudflare Access checks every request against your identity provider before it arrives, and the Gateway is set to trust that proxy. Choose it when several people need the dashboard through single sign-on. The tunnel is free, and Access is free for up to 50 users. A tunnel without Access in front would expose the Gateway.

Reverse Proxy Add-ons

Add a reverse proxy when the service should be reachable at its own web address: it terminates HTTPS on your domain and can put a login in front of an interface that is otherwise kept private.

Caddy

OpenClaw Self-Hosted with Caddy

The shortest route to a dashboard on your own domain: Caddy gets and renews the certificate by itself and passes the WebSocket connection the Control UI depends on without extra directives. OpenClaw's docs use it in two ways: with an OAuth plugin, so Caddy signs people in and hands their identity to the Gateway's trusted-proxy mode, and to publish a single webhook path for a channel such as Google Chat while everything else stays private. Caddy's address has to be listed under the Gateway's trusted proxies, or forwarded requests are rejected.

Traefik

OpenClaw Self-Hosted with Traefik

Routes to the Gateway container from Docker labels and renews Let's Encrypt certificates on its own, which suits a server that already runs other containers behind it. Traefik has no login of its own, so OpenClaw's docs pair it with a forward-auth service that checks each request and passes the user's identity in a header. Without one, keep the Gateway's token or password auth switched on. It is also the proxy that Coolify and Dokploy run underneath.

NGINX

OpenClaw Self-Hosted with NGINX

The proxy many servers already have, with certificates through Certbot. OpenClaw's example puts oauth2-proxy beside it for sign-in and sets the HTTP/1.1 upgrade headers, without which the Control UI's WebSocket never connects. A proxy that only terminates TLS is not an access control: for anything on the public internet, OpenClaw's guidance is a proxy that authenticates users and is the only network path to the Gateway.

Self Hosted Paas Add-ons

Add a self-hosted PaaS when you would rather deploy and update from a dashboard than from the command line: it installs the service from a template and brings its own reverse proxy and certificates.

Coolify

OpenClaw Self-Hosted with Coolify

A free, self-hosted deploy dashboard with a one-click OpenClaw service. The template publishes the Control UI on your domain over HTTPS behind a generated username and password, creates the gateway token, takes provider keys as environment variables, and adds a browser container for web automation. Two things to know. It runs an image that Coolify builds, not the project's official one, and the template pins a version, so check the tag before relying on it. And the result is a dashboard on the public internet behind a password, a wider exposure than the loopback default.

Dokploy

OpenClaw Self-Hosted with Dokploy

Free and self-hosted, with an OpenClaw template in its catalog that routes a domain to the service through Dokploy's bundled Traefik, with HTTPS from the dashboard and a generated username, password, and gateway token. It deploys the same Coolify-built image, so the same check on the pinned version applies. As with Coolify, the proxy comes with the platform, and no separate reverse proxy is added next to it.

Frequently Asked Questions about OpenClaw Self-Hosted

Is there a managed OpenClaw, or do I have to host it myself?

There is no first-party one. The project sells no subscription and runs no hosted service, so every managed OpenClaw comes from a third party. Hostinger sells a managed plan from $5.99 a month on a two-year term, renewing at $11.99, that takes care of the server, Docker, and updates, with AI credits already set up. DigitalOcean runs OpenClaw on App Platform, its managed container service, and newer services such as Agent 37 host an agent from about $4 a month. They save you the setup and the patching. What you give up is the reason most people self-host: the agent's memory, credentials, and connected accounts then sit on someone else's infrastructure, and you depend on how quickly that host ships OpenClaw's frequent releases. Self-hosting costs about the same and keeps all of it on a machine you control.

What size server does OpenClaw need?

Less than most self-hosted software. OpenClaw's docs give 1 vCPU, 1 GB of RAM, and about 500 MB of disk as the absolute minimum, and recommend 2 GB or more for headroom, because logs, media, several channels, and browser automation add up. On 1 GB, add swap. The model doesn't count toward any of this: it runs at the provider, so the server only carries the Gateway. Two things need more. Building the Docker image from source takes 6 GB, which is why the pre-built image is the sensible default. And a local model needs a GPU or a large-memory Mac. OpenClaw's Raspberry Pi guide says not to run one on a Pi at all, so the usual layout is the agent on the small server and Ollama or LM Studio on a stronger computer it can reach.

What needs backing up, and how do updates work?

Everything lives in one folder on the host, mounted into the container: the configuration file, SQLite databases holding credentials and model sign-ins, channel logins, and the workspace with the agent's Markdown memory. Back up that folder, or use OpenClaw's backup command, which writes a verified archive and can run on a schedule to an offsite location. Treat the archive as a secret, since sign-in tokens are stored in it unencrypted. An update is an image swap: pull the new tag and restart, and the container migrates its own state on startup after saving a copy of each database. OpenClaw releases often, so take a backup before a large jump. One caveat on restores: a WhatsApp login restored from an older backup can fall out of sync and need pairing again.

Do I need a reverse proxy or Coolify to run OpenClaw?

No. Most self-hosted software is a website that has to be published before you can use it. OpenClaw is not: you talk to it in your chat apps, which it reaches with outbound connections, and the dashboard is an admin screen that stays on the server. An SSH tunnel is enough to open it, and Tailscale makes it reachable from your phone without publishing anything. Add a reverse proxy when several people need the dashboard on a real address, and put a sign-in in front of it, which is what OpenClaw's docs describe for Caddy, Traefik, and NGINX. Coolify and Dokploy are worth it when you already run one, or want deploys and updates from a dashboard: both have an OpenClaw template that publishes the dashboard over HTTPS behind a password. The templates use an image built by Coolify, so check its version first.

OpenClaw or Hermes Agent: which should I self-host?

They are the two closest alternatives: both are free, MIT-licensed personal agents that run on a small server and answer through messaging apps. OpenClaw has the larger community by a wide margin, which shows in the number of channels, skills, and hosting guides, and its abilities are things you install and configure. Hermes Agent, from Nous Research, is built around a learning loop: it writes and refines its own skills from experience, so it changes more over time and is less predictable for it. Hermes also has a first-party managed service, Hermes Cloud, with a free tier, while a managed OpenClaw comes only from third parties. Pick OpenClaw for the broadest ecosystem and the setup most guides assume, and Hermes Agent if an agent that improves itself is the point.

Scores

Popularity5/5

OpenClaw is among the most-starred projects on GitHub, at around 390,000 stars, and running it on a small VPS or a home server is a well-documented path, with official guides for more than a dozen hosts.

Learning Curve3/5

Talking to the agent needs nothing beyond a chat app, and onboarding is a guided wizard. Getting there takes a server, Docker, an SSH tunnel, a model key, and a channel pairing, and keeping it safe means understanding what the agent is allowed to touch.

Flexibility5/5

Any of dozens of model providers, more than twenty messaging channels, installable skills and plugins, scheduled tasks, and full shell and browser access on the host. The host, the model, and the access route each swap on their own.

Performance4/5

The Gateway is a single light process that runs on 1 GB of memory and idles between messages. How fast it answers and how well it completes a task are set by the model behind it, not by the server.

Portability5/5

MIT-licensed, with state in SQLite and Markdown files in one folder that moves to any Linux host with a copy or the built-in backup command. The model is a configuration value, so changing provider needs no migration.

Tools in the OpenClaw Self-Hosted Stack

DevOps & CI/CD

Agentic AI

LLM (choose one)

Hosting (choose one)

Add-ons (optional — add any, or none)

Model Inference

Model Aggregator

Tunnel

Reverse Proxy

Self Hosted Paas

OpenClaw Self-Hosted Pricing

From ~$5/mo plus model usage Free to start

OpenClaw and Docker are free, so the fixed cost is the server: about $5 to $12 a month for a small VPS or container, or a one-time purchase for hardware at home. The model is the line that varies. On an API, mid-tier models cost $2 per million input tokens and $10 per million output, and low-cost ones a tenth of that or less; a flat plan from a provider that allows it, from about $18 a month, caps the spend. Reaching the dashboard over SSH or Tailscale costs nothing.

Server (any provider)$5–12/mo

1 GB of RAM is the minimum and 2 GB or more is recommended, which the smallest plans at most providers meet. Hardware at home is a one-time cost plus electricity.

OpenClawFree (MIT)

Open source with no paid tier. Docker is free as well.

Model usageUsage-based, or a flat plan

About $2 per million input tokens and $10 per million output on mid-tier models, and from $0.10 and $0.50 on small ones. Flat plans start around $18 a month. Usually the largest line.

Remote access (optional)Free

An SSH tunnel costs nothing, and Tailscale's Personal plan and Cloudflare Tunnel are free. The reverse proxies and the self-hosted deploy platforms are free, open-source software as well.

OpenClaw Self-Hosted System Requirements

source
CPU
1 vCPU minimum; 1-2 vCPU recommended
RAM
1 GB minimum; 2 GB or more recommended
Disk
About 500 MB for OpenClaw, plus room for the Docker image, logs, and the workspace
OS
Ubuntu LTS, or another modern Debian or Ubuntu, with Docker

From OpenClaw's FAQ on minimum VPS requirements. Building the Docker image from source needs at least 6 GB of RAM, and the pre-built image avoids that. On 1 GB the project's guides add 2 GB of swap. The model runs at the provider and isn't part of these figures; a local model needs separate, much larger hardware.