OpenClaw VPS Run your OpenClaw gateway 24/7 on a server of your own
OpenClaw is a self-hosted gateway that connects chat apps such as Telegram, WhatsApp, Discord and Slack to AI agents. To keep it answering while your own computer is off, run it on a small Linux server: here a KVM VPS with Ubuntu or Debian and full root from €4.99/month in Amsterdam, paid by card, PayPal or crypto with no ID check. There is no one-click image — you install the current release with OpenClaw's own script, and this page has the commands and the security settings to keep.
- Ubuntu or Debian, full root
- Gateway stays on loopback
- Card, PayPal or crypto
- Always-on DDoS protection
OpenClaw VPS
What runs where
- System
- Ubuntu · Debian
- Runtime
- Node.js — the installer sets it up
- Gateway port
- 18789, loopback only
- Remote access
- SSH tunnel or Tailscale
- Model
- Your provider's API key
- From
- €4.99/month
01Why a VPS
Why run OpenClaw on a VPS?
OpenClaw runs on a laptop too. Two things speak for a server: the gateway has to be up whenever a message arrives, and an agent that can run commands is better kept away from your own files.
Online while your computer sleeps
The gateway is the process your chat apps talk to. On a server it keeps answering on Telegram, WhatsApp, Discord or Slack while your laptop is shut, asleep or on the road.
A machine of its own
OpenClaw's agents can run shell commands and edit files. On a separate VPS they reach what is on that server — not your documents, your browser profiles or your password manager. A reinstall from the panel takes it back to a clean system at any time.
Full root on KVM
Your own kernel and root on a KVM virtual machine: run the installer, Docker, Tailscale or a reverse proxy, and open only the ports you choose.
A fixed monthly price
€4.99/month for the smallest plan in Amsterdam, the same every month. Prepay up to 12 months and the rate drops by up to 15%. What the model costs is billed by your model provider, not by us.
02Install
How do I install OpenClaw on a VPS?
With OpenClaw's official installer on a fresh Ubuntu or Debian server, following OpenClaw's own install and Linux guides. Five steps:
- 01
Order and log in
Pick Ubuntu 24.04 LTS or Debian 13 (Trixie) at checkout; a Linux server is online about a minute after your payment is confirmed. Log in over SSH and create a normal user with sudo rights, so the gateway does not run as root — our first-ten-minutes checklist covers that, SSH keys and updates.
- 02
Run the installer
As that user, run
curl -fsSL https://openclaw.ai/install.sh | bash. The script installs or upgrades Node.js to a supported release if needed, installs OpenClaw and then starts the onboarding, which walks you through the setup — your model provider's API key among it. OpenClaw's docs also describe an npm install if you manage Node.js yourself. - 03
Install the gateway service
If the onboarding did not install the gateway as a service, run
openclaw onboard --install-daemon: it installs it as a systemd user service.openclaw gateway statusshows whether it is running; check it once more after the first reboot. - 04
Connect a chat app
For Telegram, create a bot with @BotFather and add its token with
openclaw channels add --channel telegram --token BOT_TOKEN. WhatsApp signs in withopenclaw channels login --channel whatsapp.--helplists each channel's own options. - 05
Open the Control UI through a tunnel
On your own computer, run
ssh -N -L 18789:127.0.0.1:18789 you@your-server-ip, open http://127.0.0.1:18789/ and sign in with the gateway's token. Nothing has to be opened in the firewall: the SSH tunnel carries the connection.
# on the VPS, as your normal user
curl -fsSL https://openclaw.ai/install.sh | bash
# only if the onboarding did not install the service:
openclaw onboard --install-daemon
openclaw channels add --channel telegram --token BOT_TOKEN
openclaw gateway status
openclaw security audit
# on your own computer
ssh -N -L 18789:127.0.0.1:18789 you@your-server-ip
# then open http://127.0.0.1:18789/From OpenClaw's install and Linux guides, checked on 11 October 2026. OpenClaw moves fast: where a command here differs from the docs, the docs are right.
Prefer Docker? OpenClaw's Docker setup is official too. Use the pre-built image (OPENCLAW_IMAGE=ghcr.io/openclaw/openclaw:latest): building it from source needs at least 6 GB of RAM. Container images bind the gateway to all interfaces by default, so pair it with authentication before you start it, and read the note on Docker and UFW below. Install Docker on Ubuntu or Debian first.
Older Ubuntu and Debian releases are on the order form too, and a reinstall from the panel gives you a clean system whenever you want to start over. More on Ubuntu VPS and Debian VPS.
03Security
How do I keep an OpenClaw gateway safe on a public server?
Whoever reaches the gateway can use everything the agent can. OpenClaw's defaults are safe; on a VPS the work is not to undo them by accident.
Leave the gateway on loopback
It listens on 127.0.0.1, port 18789, by default. Reach it through an SSH tunnel or Tailscale Serve instead of opening the port; binding it to a LAN or tailnet address requires a shared secret.
Mind Docker's published ports
Ports Docker publishes skip UFW's rules: traffic to a container is routed before UFW sees it. Publish to 127.0.0.1 only, or filter in the DOCKER-USER chain, as OpenClaw's Docker guide asks.
Run the security audit
openclaw security audit reports where your configuration has drifted from the secure defaults. Run it after every change to the gateway, its channels or its tools.
One gateway per circle of trust
OpenClaw is not built for users who distrust each other. Give each person or team a gateway of its own, under a separate OS user or on a separate server.
SSH first
Decide how you administer the box before OpenClaw goes on it: SSH keys instead of passwords and a UFW firewall that lets in SSH and nothing you have not chosen.
Keep personal accounts off it
Give the agent accounts made for it. OpenClaw's docs advise against signing a shared agent's runtime into personal Google or Apple accounts, browser profiles or a password manager.
This section follows OpenClaw's security documentation, which also covers sandbox profiles that limit what an agent may touch — worth setting, because text in a message or on a web page can try to steer an agent.
04Plans
Sized by what your agent does
OpenClaw's docs set no minimum. With a hosted model the server only runs the gateway, so the smallest plan is enough to start; a browser, a Docker build or many agents are what need more.
Standard KVM
Most setupsThe most RAM per euro: 4 GB and 2 vCores for €4.99. Room for the gateway, several channels and a database next to it.
| Plan | vCores | RAM | Storage | Amsterdam |
|---|---|---|---|---|
| STANDARD KVM 12 vCores4 GB DDR420 GB | 2 | 4 GB DDR4 | 20 GB | €4.99/mo |
| STANDARD KVM 24 vCores8 GB DDR440 GBBrowser & Docker builds | 4 | 8 GB DDR4 | 40 GB | €9.99/mo |
| STANDARD KVM 36 vCores12 GB DDR460 GB | 6 | 12 GB DDR4 | 60 GB | €14.99/mo |
Hi-CPU KVM
Fast single threadsFewer GB per plan, on AMD EPYC. For agents that compile code, run test suites or render pages, where one fast thread decides how long a task takes.
| Plan | vCores | RAM | Storage | Amsterdam |
|---|---|---|---|---|
| HI-CPU 11 vCore2 GB ECC20 GB | 1 | 2 GB ECC | 20 GB | €4.99/mo |
| HI-CPU 22 vCores4 GB ECC40 GB | 2 | 4 GB ECC | 40 GB | €9.99/mo |
| HI-CPU 33 vCores6 GB ECC60 GB | 3 | 6 GB ECC | 60 GB | €14.99/mo |
Gateway with a hosted model
The model runs at your provider; the server runs one Node.js process and its channels. The €4.99 plan with 4 GB is enough to start.
Browser automation
Every Chromium tab the agent opens takes memory of its own. If your agent browses a lot, start at 8 GB (€9.99).
Docker from source
OpenClaw's docs ask for at least 6 GB of RAM to build the image from source, which 8 GB (€9.99) covers. The pre-built image skips that build.
Local models
None of our VPS plans has a GPU. A local model would run on the CPU alone — workable for small models, slow for anything bigger. Point OpenClaw at a hosted model and keep the server for the gateway.
Start small: an upgrade from the panel gives the same server more vCores, RAM and storage — your data and your IP address stay, and the new resources apply after a reboot. If the kernel kills processes for lack of memory, that is the sign to move up, or to add swap as a buffer.
Pay by card, PayPal or crypto (Bitcoin, Ethereum, USDT, Litecoin, Monero and more), with no ID check: how paying in crypto works.
05Rules
The same rules for you and your agent
Lawful automation is permitted use. The agent works with your server and your accounts, so what it does is treated as done by you.
Allowed
Our Acceptable Use Policy names “automated tasks, bots, and scripts for lawful purposes” as permitted use. A personal assistant, a team agent, coding and research agents all fall under it.
Forbidden, also for an agent
Spam, phishing, fraud, malware and botnets stay forbidden when an agent does them. You are responsible for everything that runs on your server and for what it sends.
Platform rules are yours
Telegram, WhatsApp, Discord and Slack have terms of their own for bots and automated accounts. An agent on your personal account is bound by them, and a ban there is between you and the platform.
The complete rules are in our Acceptable Use Policy. Running a classic Discord or Telegram bot instead? That is bot hosting.
06FAQ
OpenClaw VPS: questions
Everything you need to know before deploying — and a human if you need more.
Still have questions?
Real engineers on the other end: typical first response under an hour, around the clock.
< 1 hour Typical first response
24/7/365 Engineers on shift
07Use cases & related
Related plans and guides
Other servers we run for neighbouring jobs, each with its starting price, and three guides worth reading before you order.
Related planseach from €4.99/mo
- Websites, apps and game servers
Standard KVM VPS
Intel KVM with the most vCores per euro: 2 to 32 vCores in nine sizes, in Amsterdam.
- Bots, game servers and builds
AMD EPYC Hi-CPU VPS
1 to 14 AMD EPYC vCores at Standard KVM's nine prices, built for single-thread work.
- Bots that run 24/7
Discord bot hosting
A Linux VPS with full root for Discord and Telegram bots under systemd, with its own IPv4 address.
- Ubuntu servers
Ubuntu VPS
Ubuntu LTS with root over SSH and a kernel of its own, so Docker and WireGuard work without workarounds.
- Debian servers
Debian VPS
Debian with root over SSH: pick the release at checkout, reinstall a clean system from the panel.
- Paying in crypto
Anonymous crypto VPS
BTC, ETH, USDT, LTC, XMR and more through Cryptomus, against a euro invoice.
GuidesFrom the VMHeaven blog
Ready to run OpenClaw 24/7?
Enterprise-grade compute in the EU — no contracts, cancel anytime.
