OpenClawAI agentsVPSself-hostedIndia

OpenClaw Explained: How to Self-Host It on a VPS (India Guide)

·9 min read

Search interest in OpenClaw in India has exploded this year. On Google Trends (India, last 12 months), "openclaw vps" is one of the fastest-rising queries attached to the word "vps" itself. Most people searching are asking two things: what is it, and where do I run it so it stays on.


This guide answers both, using the official docs at docs.openclaw.ai as the source of truth.


What is OpenClaw?


OpenClaw is an open-source (MIT) AI assistant maintained by the OpenClaw Foundation. The pitch in its own words: "Your AI assistant, on your own hardware, in every chat app you already use."


Four pieces matter:


  • Gateway — one long-running process on your laptop or a server. It owns sessions, routing, and channel connections. This is the thing you keep alive 24/7.
  • Agents — coding-capable agents with tools, memory, sessions, and multi-agent routing.
  • Channels — plugins that connect the agent to WhatsApp, Telegram, Discord, Slack, Signal and more, so you talk to it from your phone.
  • Skills and tools — repeatable procedures the agent loads on demand, plus automation like cron jobs and webhooks.

  • You bring your own model API key (or a local model service). OpenClaw itself is free.


    OpenClaw vs n8n


    If you already run n8n (I do — see my n8n + Cloudflare Tunnel setup), the difference is simple:


  • n8n is a workflow engine. You draw the steps; it runs them the same way every time.
  • OpenClaw is an agent. You give it a goal in a chat message; it decides the steps.

  • Use n8n for anything that must be predictable (invoices, lead routing, backups). Use an agent for open-ended work (research, triage, "check why the server is slow"). They also work well together: n8n can call an agent through a webhook.


    Why a VPS and not your laptop?


    The Gateway has to be online for your WhatsApp or Telegram messages to reach the agent. A laptop sleeps, changes networks, and sits behind Jio/Airtel CGNAT. A small Linux VPS stays up and has a stable IP.


    Sizing


    The official install page does not publish a RAM minimum. Community guides converge on:


  • 2 GB RAM as the floor (1 GB boxes commonly hit out-of-memory during install)
  • 4 GB RAM, 2 vCPU as the comfortable default
  • 20–40 GB disk for logs, transcripts and tool output

  • The model runs at your provider (Claude, OpenAI, etc.), so you do not need a GPU unless you plan to run a local model on the same box.


    Picking a region from India


    For a chat agent, latency between you and the VPS matters far less than reliability. Mumbai or Bangalore regions feel snappiest; Singapore and Germany are fine too. Pick the provider whose billing works with your card or UPI and whose support you trust. Price-check at the time you buy — VPS pricing and GST treatment change often.


    Install


    OpenClaw needs Node.js 24.16+ or 26.1+ (Node 26 recommended). The installer script will install Node for you if it is missing.


    SSH into a fresh Ubuntu server as a normal (non-root) user, then:


    
    curl -fsSL https://openclaw.ai/install.sh | bash
    

    This detects your OS, installs Node if needed, installs the CLI, and starts onboarding. Piping a script into bash runs remote code, so read it first if you prefer — the docs have an "Installer internals" page.


    If you manage Node yourself, the npm route is:


    
    npm install -g openclaw@latest --allow-scripts=openclaw
    openclaw onboard --install-daemon
    

    (On npm 11.15 or older, drop --allow-scripts=openclaw.) Docker and Podman installs are also documented if you prefer containers.


    Verify


    
    openclaw --version
    openclaw doctor
    openclaw gateway status
    

    If the shell says openclaw: command not found, npm's global bin directory is not on your PATH. Run npm prefix -g and add its bin folder to PATH in ~/.bashrc.


    Keep it running 24/7


    openclaw onboard --install-daemon (or openclaw gateway install) registers the Gateway as a systemd user service on Linux. Because it is a user service, it stops when you log out unless lingering is enabled:


    
    sudo loginctl enable-linger $USER
    

    Reboot the VPS once and run openclaw gateway status to confirm it comes back by itself. Do this before you rely on it.


    Connect WhatsApp or Telegram


    Channels are configured per plugin — follow the channels docs for the exact steps for each app. Telegram is the easiest first channel: create a bot with BotFather, paste the token, done.


    For WhatsApp, decide early whether you are using the official Meta Cloud API or an unofficial bridge. The official route costs money per template message (see my WhatsApp Business API pricing in India breakdown); unofficial bridges are free but risk a number ban. I cover the trade-offs of the unofficial route in my OpenWA + n8n guide.


    Security: the settings you must not skip


    An agent with shell access on a public server is a juicy target. The security docs are worth reading in full; the short version:


    1. Keep the Gateway on loopback. Normal installs bind to localhost by default. Container images default to an exposed bind — if you use Docker, turn on auth and follow the exposure runbook before opening any port.

    2. Reach it remotely through SSH or Tailscale, not a public port. An SSH tunnel is enough:

    ```bash

    ssh -N -L 18789:127.0.0.1:18789 you@your-vps

    ```

    (Use the port your Gateway reports in openclaw gateway status.)

    3. Leave DM pairing on. By default, unknown senders get a pairing code instead of a reply. Never switch a channel to open on a personal agent.

    4. Sandbox tools. Configure per-agent permissions and read-only modes; avoid "full access" on a server holding anything you care about.

    5. Run the audit after every config change:

    ```bash

    openclaw security audit

    ```

    It flags drift from safe defaults, including any dangerously* flags left on.

    6. One trust boundary per Gateway. If several people will use it, give each their own Gateway, credentials and ideally OS user.


    Also basic VPS hygiene: SSH keys only, ufw allowing just port 22, unattended security updates.


    Checklist


  • [ ] VPS with ≥2 GB RAM (4 GB comfortable), Ubuntu LTS, non-root user
  • [ ] curl -fsSL https://openclaw.ai/install.sh | bash
  • [ ] openclaw doctor clean
  • [ ] Gateway installed as a service + loginctl enable-linger
  • [ ] Survives a reboot
  • [ ] One channel connected, DM pairing on
  • [ ] openclaw security audit clean
  • [ ] Remote access via SSH tunnel or Tailscale only

  • If you want help wiring OpenClaw into an existing n8n or WhatsApp setup for your business, get in touch.

    Built something similar or want to talk through the architecture? Get in touch.