OpenClaw on a VPS: Install and Secure It (2026 Guide)

OpenClaw is an open-source AI agent that acts for you from chat apps. Run it on its own VPS, keep the gateway on loopback, and reach it over SSH or Tailscale.
When I first wrote about OpenClaw in February 2026, it was the most talked-about open-source project of the year: an assistant you message on WhatsApp or Telegram that actually reads your email, runs commands and automates tasks. Since then it has also become a security lesson. Researchers found tens of thousands of gateways exposed to the internet, several serious CVEs, and over a thousand malicious skills on its ClawHub registry. I now set it up for clients the way I'd set up any service with shell access: isolated, private and audited. This guide explains what OpenClaw is and walks through that setup on Ubuntu.
Key takeaways
- OpenClaw is an agent, not a chatbot. It runs on your machine or server and can execute commands, use a browser and act in your accounts.
- Give it its own VPS and its own Linux user, not your laptop or a server with production data.
- Keep the gateway on loopback (
127.0.0.1:18789, the default) and reach it through an SSH tunnel or Tailscale Serve. Never open it to the internet. - Treat ClawHub skills like untrusted code. Malicious skills that steal credentials have been found there repeatedly.
- Run
openclaw security auditafter setup and after every config change, and keep OpenClaw updated.
What is OpenClaw?
OpenClaw is a free, open-source personal AI assistant, first released in November 2025 by developer Peter Steinberger under the names Clawdbot and then Moltbot. It's now maintained by the OpenClaw Foundation. You install a gateway on a computer or server, connect a model (Claude, GPT, or a local model through Ollama), and talk to it through chat apps you already use: Telegram, WhatsApp, Slack, Discord, Signal and others.
The difference from ChatGPT is that OpenClaw takes actions. With the right permissions it can sort email, manage a calendar, browse websites, edit files, run shell commands and call APIs. It keeps memory between conversations and can be extended with "skills" from the community registry, ClawHub. That power is the reason to use it, and the reason it needs careful hosting.
Is OpenClaw safe?
OpenClaw ships with sensible defaults: the gateway binds to loopback, unknown people who message your bot get a pairing code instead of a response, and group chats are allowlisted. The incidents in 2026 mostly came from people changing those defaults or trusting third-party code:
- Exposed gateways. Internet scans found very large numbers of OpenClaw gateways reachable from the public internet, many without authentication. Anyone who reaches an unauthenticated gateway can control the agent.
- Vulnerabilities. CVE-2026-25253 (CVSS 8.8), disclosed in January 2026, let a crafted link leak the gateway token through the Control UI. More high-severity CVEs followed. Old versions stay vulnerable.
- Malicious skills. Security firms including Bitdefender reported skills on ClawHub that installed info-stealing malware, disguised as productivity tools. By April 2026 more than 1,400 had been identified.
So: safe enough when isolated, updated and kept private; risky on your main laptop with every permission switched on.
Step 1: Give OpenClaw its own server and user
Use a fresh, small Ubuntu 24.04 VPS that holds nothing else: no production database, no client files, no SSH keys to other servers. If the agent is tricked by a prompt injection or a bad skill, the damage stays in that box. Harden it first with my Ubuntu 24.04 hardening checklist (key-only SSH, firewall, automatic updates), then create a normal user for OpenClaw:
sudo adduser --disabled-password --gecos "" claw sudo install -d -m 700 -o claw -g claw /home/claw/.ssh sudo cp ~/.ssh/authorized_keys /home/claw/.ssh/ && sudo chown claw:claw /home/claw/.ssh/authorized_keys sudo ufw default deny incoming sudo ufw allow OpenSSH sudo ufw enable
Don't add claw to the sudo group. The agent shouldn't be able to become root.
Step 2: Install OpenClaw
Log in as claw. OpenClaw needs Node.js 24.16+ or 26.1+; the official installer adds a suitable Node version if it's missing. As with any curl | bash, you can download the script and read it first:
curl -fsSL https://openclaw.ai/install.sh -o install.sh less install.sh bash install.sh
The installer starts onboarding, which asks for your workspace, model provider and API key, gateway settings and chat channels. Keep the gateway bind on loopback when asked. To install the gateway as a service that survives reboots and logouts:
openclaw onboard --install-daemon sudo loginctl enable-linger claw # keep the user service running without a login systemctl --user status openclaw-gateway openclaw doctor
On Linux the gateway runs as a systemd user service. openclaw doctor checks the install and config, and openclaw doctor --fix repairs legacy settings after upgrades.
Step 3: Keep the gateway private
The gateway's WebSocket and Control UI listen on 127.0.0.1:18789 by default. Leave it that way. Check it:
ss -tlnp | grep 18789 # must show 127.0.0.1:18789, never 0.0.0.0 or [::]
To use the Control UI or the CLI from your laptop, forward the port over SSH:
ssh -N -L 18789:127.0.0.1:18789 claw@your-vps # then open http://127.0.0.1:18789 on your laptop
If you want access from your phone or several devices, Tailscale Serve is the officially supported option: it publishes the loopback port only inside your private tailnet, with HTTPS. Don't put the gateway behind a public Nginx reverse proxy unless you follow OpenClaw's exposure runbook and use trusted-proxy authentication. And if you run OpenClaw in Docker, remember that published container ports bypass UFW; see Docker bypasses UFW.
Step 4: Sandbox tools and vet skills
OpenClaw can run tool calls inside Docker or Podman sandboxes instead of directly on the host. The documented minimal setup in ~/.openclaw/openclaw.json:
{
agents: {
defaults: {
sandbox: {
mode: "non-main",
scope: "session",
workspaceAccess: "none",
},
},
},
}
Then be strict about skills:
- Install as few as possible, from authors you can identify.
- Read the skill before installing. Red flags: install steps that download and run binaries, obfuscated scripts, requests for credentials unrelated to the task.
- Don't give the agent your main email, password manager or crypto wallets. Use separate accounts with limited scopes where you can.
- Watch for prompt injection. Any web page or email the agent reads can contain instructions. Keep risky tools behind approval.
Step 5: Audit and update
openclaw security audit openclaw status
openclaw security audit checks your config against OpenClaw's security baseline (exposure, auth, channel access, tool permissions) and lists findings in priority order. Run it after setup, after every config change and after updates. Then update regularly: most of 2026's serious CVEs were fixed quickly, and the exposed instances that got abused were usually old versions.
What is OpenClaw good for?
- Personal admin: inbox triage, reminders, calendar, summaries sent to your phone.
- Developer chores: checking CI, summarising logs, opening issues, running scripts in a sandbox.
- Research: browsing, collecting and summarising sources on a schedule.
- Private AI: paired with a local model, nothing leaves your server. My guide to self-hosting an LLM with Ollama covers that side.
If you're building your own tools for agents instead, see how to build an MCP server in TypeScript.
Frequently asked questions
What is OpenClaw used for?
OpenClaw is a self-hosted AI agent you control through chat apps like Telegram or WhatsApp. People use it to automate email, calendars, research, browsing and developer tasks, because it can take actions instead of only answering.
Is OpenClaw free?
OpenClaw itself is free and open source. You pay for the server it runs on and for the AI model it uses, unless you run a local model with Ollama.
Can I run OpenClaw on a VPS?
Yes, and it's the setup I recommend: a dedicated Ubuntu VPS, a non-root user, the gateway installed as a systemd user service, and access over an SSH tunnel or Tailscale, with no public port.
Is it safe to install skills from ClawHub?
Only after reviewing them. Security researchers have found more than a thousand malicious skills on ClawHub that stole credentials. Install few skills, read their code and install steps, and run tools in a sandbox.
What port does OpenClaw use?
The gateway listens on port 18789 on loopback (127.0.0.1) by default, configurable with gateway.port. Keep it off public interfaces.
Want OpenClaw set up securely?
I deploy OpenClaw and other self-hosted AI tools on isolated, hardened Linux servers with private access, sandboxing, backups and updates, so you get the automation without exposing your accounts. See my Linux system admin services or tell me what you want to automate.
Written by
MD Rakibul Islam Rakib
Full-stack developer, DevOps engineer and Linux system administrator with 5+ years of production experience. I deploy, harden and fix servers and web apps for clients worldwide, and everything in this article runs on real servers I manage, including this site.
- OpenClaw
- OpenClaw VPS
- OpenClaw security
- self-hosted AI agent
- ClawHub
- Tailscale
- Ubuntu


