VMHeaven

OpenClaw VPS Run your OpenClaw gateway 24/7 on a server of your own

OpenClaw is a self-hosted gateway that connects chat apps such as Telegram, WhatsApp, Discord and Slack to AI agents. To keep it answering while your own computer is off, run it on a small Linux server: here a KVM VPS with Ubuntu or Debian and full root from €4.99/month in Amsterdam, paid by card, PayPal or crypto with no ID check. There is no one-click image — you install the current release with OpenClaw's own script, and this page has the commands and the security settings to keep.

  • Ubuntu or Debian, full root
  • Gateway stays on loopback
  • Card, PayPal or crypto
  • Always-on DDoS protection

OpenClaw VPS

What runs where

System
Ubuntu · Debian
Runtime
Node.js — the installer sets it up
Gateway port
18789, loopback only
Remote access
SSH tunnel or Tailscale
Model
Your provider's API key
From
€4.99/month

01Why a VPS

Why run OpenClaw on a VPS?

OpenClaw runs on a laptop too. Two things speak for a server: the gateway has to be up whenever a message arrives, and an agent that can run commands is better kept away from your own files.

Online while your computer sleeps

The gateway is the process your chat apps talk to. On a server it keeps answering on Telegram, WhatsApp, Discord or Slack while your laptop is shut, asleep or on the road.

A machine of its own

OpenClaw's agents can run shell commands and edit files. On a separate VPS they reach what is on that server — not your documents, your browser profiles or your password manager. A reinstall from the panel takes it back to a clean system at any time.

Full root on KVM

Your own kernel and root on a KVM virtual machine: run the installer, Docker, Tailscale or a reverse proxy, and open only the ports you choose.

A fixed monthly price

€4.99/month for the smallest plan in Amsterdam, the same every month. Prepay up to 12 months and the rate drops by up to 15%. What the model costs is billed by your model provider, not by us.

02Install

How do I install OpenClaw on a VPS?

With OpenClaw's official installer on a fresh Ubuntu or Debian server, following OpenClaw's own install and Linux guides. Five steps:

  1. 01

    Order and log in

    Pick Ubuntu 24.04 LTS or Debian 13 (Trixie) at checkout; a Linux server is online about a minute after your payment is confirmed. Log in over SSH and create a normal user with sudo rights, so the gateway does not run as root — our first-ten-minutes checklist covers that, SSH keys and updates.

  2. 02

    Run the installer

    As that user, run curl -fsSL https://openclaw.ai/install.sh | bash. The script installs or upgrades Node.js to a supported release if needed, installs OpenClaw and then starts the onboarding, which walks you through the setup — your model provider's API key among it. OpenClaw's docs also describe an npm install if you manage Node.js yourself.

  3. 03

    Install the gateway service

    If the onboarding did not install the gateway as a service, run openclaw onboard --install-daemon: it installs it as a systemd user service. openclaw gateway status shows whether it is running; check it once more after the first reboot.

  4. 04

    Connect a chat app

    For Telegram, create a bot with @BotFather and add its token with openclaw channels add --channel telegram --token BOT_TOKEN. WhatsApp signs in with openclaw channels login --channel whatsapp. --help lists each channel's own options.

  5. 05

    Open the Control UI through a tunnel

    On your own computer, run ssh -N -L 18789:127.0.0.1:18789 you@your-server-ip, open http://127.0.0.1:18789/ and sign in with the gateway's token. Nothing has to be opened in the firewall: the SSH tunnel carries the connection.

Install and connect
# on the VPS, as your normal user
curl -fsSL https://openclaw.ai/install.sh | bash
# only if the onboarding did not install the service:
openclaw onboard --install-daemon
openclaw channels add --channel telegram --token BOT_TOKEN
openclaw gateway status
openclaw security audit

# on your own computer
ssh -N -L 18789:127.0.0.1:18789 you@your-server-ip
# then open http://127.0.0.1:18789/

From OpenClaw's install and Linux guides, checked on 11 October 2026. OpenClaw moves fast: where a command here differs from the docs, the docs are right.

Prefer Docker? OpenClaw's Docker setup is official too. Use the pre-built image (OPENCLAW_IMAGE=ghcr.io/openclaw/openclaw:latest): building it from source needs at least 6 GB of RAM. Container images bind the gateway to all interfaces by default, so pair it with authentication before you start it, and read the note on Docker and UFW below. Install Docker on Ubuntu or Debian first.

Older Ubuntu and Debian releases are on the order form too, and a reinstall from the panel gives you a clean system whenever you want to start over. More on Ubuntu VPS and Debian VPS.

03Security

How do I keep an OpenClaw gateway safe on a public server?

Whoever reaches the gateway can use everything the agent can. OpenClaw's defaults are safe; on a VPS the work is not to undo them by accident.

Leave the gateway on loopback

It listens on 127.0.0.1, port 18789, by default. Reach it through an SSH tunnel or Tailscale Serve instead of opening the port; binding it to a LAN or tailnet address requires a shared secret.

Mind Docker's published ports

Ports Docker publishes skip UFW's rules: traffic to a container is routed before UFW sees it. Publish to 127.0.0.1 only, or filter in the DOCKER-USER chain, as OpenClaw's Docker guide asks.

Run the security audit

openclaw security audit reports where your configuration has drifted from the secure defaults. Run it after every change to the gateway, its channels or its tools.

One gateway per circle of trust

OpenClaw is not built for users who distrust each other. Give each person or team a gateway of its own, under a separate OS user or on a separate server.

SSH first

Decide how you administer the box before OpenClaw goes on it: SSH keys instead of passwords and a UFW firewall that lets in SSH and nothing you have not chosen.

Keep personal accounts off it

Give the agent accounts made for it. OpenClaw's docs advise against signing a shared agent's runtime into personal Google or Apple accounts, browser profiles or a password manager.

This section follows OpenClaw's security documentation, which also covers sandbox profiles that limit what an agent may touch — worth setting, because text in a message or on a web page can try to steer an agent.

04Plans

Sized by what your agent does

OpenClaw's docs set no minimum. With a hosted model the server only runs the gateway, so the smallest plan is enough to start; a browser, a Docker build or many agents are what need more.

Standard KVM

Most setups
Intel · DDR4 ECC

The most RAM per euro: 4 GB and 2 vCores for €4.99. Room for the gateway, several channels and a database next to it.

Amsterdam In stockFrankfurt Sold out
PlanAmsterdam
STANDARD KVM 12 vCores4 GB DDR420 GB€4.99/mo
STANDARD KVM 24 vCores8 GB DDR440 GBBrowser & Docker builds€9.99/mo
STANDARD KVM 36 vCores12 GB DDR460 GB€14.99/mo
All 9 Standard KVM plans

Hi-CPU KVM

Fast single threads
AMD EPYC · ECC

Fewer GB per plan, on AMD EPYC. For agents that compile code, run test suites or render pages, where one fast thread decides how long a task takes.

Amsterdam In stockFrankfurt Sold out
PlanAmsterdam
HI-CPU 11 vCore2 GB ECC20 GB€4.99/mo
HI-CPU 22 vCores4 GB ECC40 GB€9.99/mo
HI-CPU 33 vCores6 GB ECC60 GB€14.99/mo
All 9 Hi-CPU KVM plans

Gateway with a hosted model

The model runs at your provider; the server runs one Node.js process and its channels. The €4.99 plan with 4 GB is enough to start.

Browser automation

Every Chromium tab the agent opens takes memory of its own. If your agent browses a lot, start at 8 GB (€9.99).

Docker from source

OpenClaw's docs ask for at least 6 GB of RAM to build the image from source, which 8 GB (€9.99) covers. The pre-built image skips that build.

Local models

None of our VPS plans has a GPU. A local model would run on the CPU alone — workable for small models, slow for anything bigger. Point OpenClaw at a hosted model and keep the server for the gateway.

Start small: an upgrade from the panel gives the same server more vCores, RAM and storage — your data and your IP address stay, and the new resources apply after a reboot. If the kernel kills processes for lack of memory, that is the sign to move up, or to add swap as a buffer.

Pay by card, PayPal or crypto (Bitcoin, Ethereum, USDT, Litecoin, Monero and more), with no ID check: how paying in crypto works.

05Rules

The same rules for you and your agent

Lawful automation is permitted use. The agent works with your server and your accounts, so what it does is treated as done by you.

Allowed

Our Acceptable Use Policy names “automated tasks, bots, and scripts for lawful purposes” as permitted use. A personal assistant, a team agent, coding and research agents all fall under it.

Forbidden, also for an agent

Spam, phishing, fraud, malware and botnets stay forbidden when an agent does them. You are responsible for everything that runs on your server and for what it sends.

Platform rules are yours

Telegram, WhatsApp, Discord and Slack have terms of their own for bots and automated accounts. An agent on your personal account is bound by them, and a ban there is between you and the platform.

The complete rules are in our Acceptable Use Policy. Running a classic Discord or Telegram bot instead? That is bot hosting.

06FAQ

OpenClaw VPS: questions

Everything you need to know before deploying — and a human if you need more.

Still have questions?

Real engineers on the other end: typical first response under an hour, around the clock.

< 1 hour Typical first response

24/7/365 Engineers on shift

No. OpenClaw runs on macOS, Linux and Windows, so a computer of your own works too.

From €4.99 a month for the smallest Standard KVM plan in Amsterdam (2 vCores, 4 GB RAM), and up to 15% less when you prepay 12 months. OpenClaw itself is free and MIT-licensed; the model you connect is billed by its provider.

For the gateway with a hosted model, the €4.99 plan. Take 8 GB (€9.99) if the agent drives a browser a lot or if you build the Docker image from source, which OpenClaw's docs say needs at least 6 GB of RAM. You can upgrade from the panel later without losing data.

No. You install OpenClaw with the project's official script on a fresh Ubuntu or Debian server; the commands are on this page. That way you get the current release straight from the project, and a reinstall from the panel takes you back to a clean system at any time.

Both are official. The script is the shortest way on a VPS. Docker keeps OpenClaw in a container: use the pre-built image unless the server has 6 GB of RAM for a source build, and remember that ports Docker publishes are not filtered by UFW.

Yes. Pay by card, PayPal or crypto (Bitcoin, Ethereum, USDT, Litecoin, Monero and more) at the same price. Sign-up asks for an e-mail address, your name, a password and a postal address for the invoice, and never for an ID document.

Linux: OpenClaw's docs call the CLI the simplest option for a headless server, and every command on this page is for Ubuntu or Debian. OpenClaw also has a PowerShell installer for Windows, if the agent needs Windows software next to it; on a Windows Server VPS you would follow OpenClaw's Windows instructions instead.

07Use cases & related

Related plans and guides

Other servers we run for neighbouring jobs, each with its starting price, and three guides worth reading before you order.

Related planseach from €4.99/mo

  • Websites, apps and game servers

    Standard KVM VPS

    Intel KVM with the most vCores per euro: 2 to 32 vCores in nine sizes, in Amsterdam.

  • Bots, game servers and builds

    AMD EPYC Hi-CPU VPS

    1 to 14 AMD EPYC vCores at Standard KVM's nine prices, built for single-thread work.

  • Bots that run 24/7

    Discord bot hosting

    A Linux VPS with full root for Discord and Telegram bots under systemd, with its own IPv4 address.

  • Ubuntu servers

    Ubuntu VPS

    Ubuntu LTS with root over SSH and a kernel of its own, so Docker and WireGuard work without workarounds.

  • Debian servers

    Debian VPS

    Debian with root over SSH: pick the release at checkout, reinstall a clean system from the panel.

  • Paying in crypto

    Anonymous crypto VPS

    BTC, ETH, USDT, LTC, XMR and more through Cryptomus, against a euro invoice.

GuidesFrom the VMHeaven blog

Ready to run OpenClaw 24/7?

Enterprise-grade compute in the EU — no contracts, cancel anytime.