dotsagent.io
Language:English
Run · self-hosting

Self-hosting OpenClaw

OpenClaw is an open-source, MIT-licensed personal agent gateway: a single process that links your chat apps to the model providers you pick and runs tools for you. This section shows how to install it on a laptop, a VPS, Docker or a Raspberry Pi, connect models and Telegram, reach it remotely and lock it down.

Latest release
2026.9.7 · September 30, 2026
Extended stable
2026.8.33
License
MIT · openclaw/openclaw · 391,000 GitHub stars
Runtime
Node.js 24.16+ / 26.1+
Minimum host
1 vCPU, 1 GB RAM, 500 MB disk
Default port
127.0.0.1:18789
Config file
~/.openclaw/openclaw.json

Quick install

The installer script sets up Node and the openclaw CLI, then starts onboarding. It provisions Node 26 on macOS and Node 24 LTS on Linux; on native Windows, use the PowerShell installer.

macOS · Linux · WSL2
curl -fsSL https://openclaw.ai/install.sh | bash
Windows PowerShell
iwr -useb https://openclaw.ai/install.ps1 | iex

Never publish the gateway port to the internet: OpenClaw binds to loopback and requires a token by default, so leave both in place. Internet scans during 2026 have counted exposed OpenClaw gateways in the tens of thousands.

Step-by-step guides

Hardened baseline

These values come from the hardened baseline in the OpenClaw docs. Start from them, relax a setting only when a workflow needs it, and run the security audit again whenever you change one.

SettingValueWhy it matters
gateway.bindloopbackOnly processes on the same machine can reach the gateway. Use an SSH tunnel or Tailscale for remote access.
gateway authtokenEvery client must present the token. Use 24 characters or more; the audit warns on shorter tokens.
session.dmScopeper-channel-peerEach sender on each channel gets a separate session, so no one sees another person's context.
tools.profilemessagingStarts the agent from a narrow, messaging-focused tool set instead of every available tool.
fs.workspaceOnlytrueKeeps file tools inside the agent workspace, away from SSH keys, credentials and the rest of the disk.
exec.securitydenyBlocks shell commands outright. On gateway hosts the default is full, which allows any command.
exec.askalwaysIf you later relax exec.security, every command waits for approval; askFallback denies when nobody answers.
elevated.enabledfalseTurns off the /elevated chat command, so no sender can switch the agent into elevated mode.
dmPolicypairingNew senders receive a code that you must approve. Codes expire after an hour; at most three wait.
groups.requireMentiontrueIn group chats the agent answers only when mentioned, not every message anyone posts.

Chat channels

Telegram, WebChat, A2A and Reef ship in core; the others are official plugins. Telegram uses long polling by default, so it needs no public webhook URL.

TelegramWebChatA2AReefWhatsAppDiscordSlackSignaliMessageMatrixMicrosoft TeamsGoogle ChatLINEMattermostIRCNostrTwitchZaloFeishuSMS (Twilio)Nextcloud TalkQQSynology ChatTlon

Name history

Peter Steinberger started the project in November 2025 under the name Clawdbot. It became Moltbot on 27 January 2026 after a trademark request from Anthropic, and OpenClaw two days later, on 29 January 2026. The OpenClaw Foundation, a US 501(c)(3) non-profit, was announced on 8 July 2026.

OpenClaw questions

Is OpenClaw free to self-host?

Yes. OpenClaw is MIT-licensed and its source is on GitHub at openclaw/openclaw. You pay for the machine it runs on and for any model API calls, unless you serve models locally.

What are the minimum requirements for OpenClaw?

The docs list 1 vCPU, 1 GB RAM and about 500 MB of disk, with Node.js 24.16+ or 26.1+. They recommend 1–2 vCPU and 2 GB RAM or more. These figures assume cloud model APIs; running models locally needs far more memory.

Which port does the OpenClaw gateway use?

Port 18789, bound to 127.0.0.1 by default. One process serves WebSocket, HTTP and the dashboard on it. You can change it with gateway.port, the --port flag or OPENCLAW_GATEWAY_PORT, but do not open it to the internet.

Does OpenClaw run on Windows?

Yes. The install page lists the native Windows Hub app, the PowerShell installer and WSL2. On Windows the background service is a Scheduled Task. Parts of the FAQ still mention only WSL2.

Is OpenClaw safe to run on my machine?

It can run commands and touch files on its host, so the settings matter. Gateway auth is required and the bind is loopback by default, but sandboxing is off and exec.security is full on gateway hosts. Apply the hardened baseline and run openclaw security audit --deep.

Where does OpenClaw keep its configuration?

The config file is ~/.openclaw/openclaw.json and the agent workspace is ~/.openclaw/workspace. Include both in your backups and copy them when you move to a new host.

Sources

  1. docs.openclaw.ai/install
  2. docs.openclaw.ai/gateway/security/hardened-baseline
  3. docs.openclaw.ai/gateway/security/network-exposure
  4. docs.openclaw.ai/channels
  5. docs.openclaw.ai/vps

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026