Run OpenClaw on a VPS
Put OpenClaw on a small Linux server so the agent stays online when your laptop is off, without opening the gateway to the internet.
You need an SSH key and an API key for a model provider. The OpenClaw docs also have provider-specific guides for Hetzner, DigitalOcean, Oracle Cloud, GCP, Azure, Fly.io and others.
Choose and prepare the server
Pick a VPS with 1–2 vCPU and 2 GB RAM, the recommended size when models run through cloud APIs; 1 vCPU and 1 GB RAM is the floor. Install a current Ubuntu LTS release, log in with an SSH key instead of a password, and set the firewall to allow SSH only. Port 18789 stays closed.
Install without onboarding
--no-onboard installs Node 24 LTS and the CLI but skips the wizard, so you can run setup as a separate step and read each prompt over SSH.
shell curl -fsSL https://openclaw.ai/install.sh | bash -s -- --no-onboardOnboard and install the service
The wizard writes ~/.openclaw/openclaw.json and generates the gateway token. --install-daemon registers the gateway as the systemd user service openclaw-gateway.service, so it keeps running after you log out of SSH.
shell openclaw onboard --install-daemonCheck the status and audit
gateway status confirms the service is up. security audit --deep runs the extended checks and flags weak settings, such as a token shorter than 24 characters.
shell openclaw gateway status openclaw security audit --deepOpen the dashboard through SSH
Run this on your own computer, not on the server. It forwards local port 18789 to the gateway's loopback address, so http://127.0.0.1:18789/ opens the remote dashboard while the port stays closed to everyone else. -N means no remote command runs; close the terminal to end the tunnel.
shell ssh -N -L 18789:127.0.0.1:18789 user@gateway-host
Do not switch gateway.bind to lan or auto on a public server to reach the dashboard. Use the SSH tunnel, or Tailscale Serve from the remote access guide.