verifier.org

best 12 openclaw hosting services

ranked on the thing that actually matters for this software — what the gateway is exposed to on first boot — then on price, setup and who patches it afterwards.

last reviewed 26 jul 2026 · 12 tools tested ·list curated by Onur Ozcanxin

the short version
best overallDigitalOceananyone who wants openclaw running today without spending the evening reading about firewall rules.93/100runner-upOVHcloudpeople who will follow a good install guide and would rather spend the saving on model credits.89/100best free optionLinode (Akamai)buyers who want an official one-click and will genuinely keep the instance updated themselves.83/100

openclaw is the most-installed self-hosted ai agent there is, and in february 2026 it became a cautionary tale: tens of thousands of instances were found sitting on the public internet with the control interface open and no authentication, leaking api keys, oauth tokens and chat histories. a one-click remote-code-execution bug rated 8.8 landed in the same window.

the software fixed this. v2026.7.1, released on 13 july, ships real hardening — token and secret protection, external gateway supervision, scoped approvals. but a hosting decision made today still determines what your instance looks like on first boot, and the providers differ enormously on that. this ranking weighs gateway defaults above price, which is why the cheapest box on the list is not at the top and the provider with no one-click at all sits second.

there is a second bill nobody mentions. openclaw needs a server and, separately, a model — openrouter, an api key, a subscription, or something local. only three entries here bundle any model access, and the credit allowances they include are small enough that you will still be paying someone else. our hermes agent hosting ranking covers the same split for the other major agent.

the noise around this query is worse than any category we've covered. hostinger publishes its own 'best openclaw vps hosting providers' ranking — a host grading hosts, with itself on the list. at least fourteen providers launched into this niche in 2026 alone. one of them blocks automated access to its own pages entirely, which is why it isn't ranked below.

advertisement
  1. 1

    DigitalOcean

    the only one-click on this list that arrives already hardened, built and maintained by the provider itself.

    93/100

    verdictthe safest default in the category by a clear margin — you pay roughly double the cheap boxes for a deployment that isn't exposed the moment it boots.

    best for
    anyone who wants openclaw running today without spending the evening reading about firewall rules.
    price
    $12/mo
    pricing note
    basic droplet, 1 vcpu / 2 gb / 50 gb ssd; per-second billing
    free tier
    yes
    type
    vps
    ram at entry
    2 gb
    openclaw setup
    one-click, in-house
    gateway security
    hardened by default
    billing
    per-second

    the marketplace image does the things the february incident proved people don't do themselves: fail2ban blocking abusive requests, unattended-upgrades patching the os without being asked, caddy terminating tls with a real certificate, agents isolated in containers, and access gated behind a gateway key plus an explicit device-pairing step. digitalocean maintains it in-house rather than shipping a community package.

    it also sells the surrounding commitment. there is a dedicated 'ai agents' marketplace category — openclaw sits in it as a staff pick alongside opencode and zeroclaw — which tells you this is a supported product line rather than a listing somebody uploaded and forgot.

    two marks against it. the price is roughly double hetzner's for half the memory, and the marketplace listing displays two different version numbers in two places, which is a small thing that undermines the 'we maintain this' claim slightly. neither is enough to move it off the top.

    pros
    • +hardening is on by default: fail2ban, auto-patching, tls, container isolation
    • +gateway key plus device pairing before first access
    • +app maintained in-house, in a dedicated ai agents category
    • +per-second billing and a signup credit
    cons
    • double hetzner's price for half the ram
    • listing shows inconsistent version numbers
    • 4 gb tier doubles to $24/mo
  2. 2

    OVHcloud

    no one-click at all, and still the second-safest way to run this — because the official guide binds the gateway to the local network.

    89/100

    verdictthe best value on this list once security is priced in — half digitalocean's cost, 4 gb instead of 2, and defaults that are arguably stricter.

    best for
    people who will follow a good install guide and would rather spend the saving on model credits.
    price
    $5.35/mo
    pricing note
    vps-1: 2 vcores / 4 gb / 40 gb nvme, no commitment; $4.54/mo on a 12-month prepay
    free tier
    no
    type
    vps
    ram at entry
    4 gb
    openclaw setup
    official guide
    gateway security
    lan-bound + token
    billing
    monthly or 12-mo prepay

    ovhcloud's own install guide is the quiet star of this category. it configures the gateway with bind:lan — local network only, not the public internet — requires a gateway token and manual device pairing before first access, puts traefik and let's encrypt in front, and runs the agent in docker. that is a stricter posture than several vendors who advertise a one-click.

    the hardware is the same bargain it is everywhere else: 2 vcores, 4 gb and nvme for $5.35 month-to-month, with daily backups and anti-ddos included rather than sold as extras.

    what you don't get is a button. this is a documented script on a standard vps, so the ten minutes of setup are yours, and the advertised $4.54 requires a year prepaid with auto-renewal. the pattern is deliberate on ovh's side — it runs the same play for n8n — but it does mean the experience is a guide rather than a product.

    pros
    • +official guide binds the gateway to lan, not the public internet
    • +gateway token and device pairing before first access
    • +4 gb nvme for around $5 with daily backups included
    • +traefik and let's encrypt configured for you
    cons
    • no marketplace one-click — you run the documented installer
    • headline price needs a 12-month prepay with auto-renewal
    • apac 'unlimited' traffic throttles after a quota
  3. 3

    Hostinger

    a real managed openclaw from a real company — that won't tell you what the managed plan costs.

    85/100

    verdictthe most credible managed option here — an established host with genuine update and backup commitments — held back by two pieces of pricing opacity it has no excuse for.

    best for
    non-technical buyers who want someone else to own updates and backups, and will ask for the price at checkout.
    price
    $6.49/mo
    pricing note
    vps docker template kvm1: 1 vcpu / 4 gb / 50 gb nvme, promo rate on a 2-year term, renews at $11.99; the separate managed 1-click plan's own price is not published
    free tier
    no
    type
    managed
    ram at entry
    4 gb
    openclaw setup
    one-click
    gateway security
    token gated
    billing
    2-yr prepay for the promo rate

    hostinger is the only large, long-established hosting brand that built a managed openclaw product rather than a tutorial. the managed plan handles version updates on one click, takes weekly backups, adds ddos protection and malware scanning, and issues a gateway token through its control panel instead of a password — a sensible pattern for this software.

    the opacity is the problem. the dedicated managed plan's price does not appear on its own pages; the figure above is the self-managed docker template, at a promo rate that requires two years upfront and renews at nearly double. and the bundled ai credits contradict themselves — hostinger's support docs say initial credits are included with the plan, while hostinger's blog tells you to go buy nexos.ai credits.

    worth knowing where you're reading, too: hostinger also publishes its own 'best openclaw vps hosting providers' ranking, with itself on it. the product here is good enough that it didn't need to.

    pros
    • +genuine managed plan: one-click updates, weekly backups, malware scanning
    • +gateway token issued through the control panel, not a password
    • +large established company with real support
    • +4 gb at the entry template, not 2
    cons
    • managed plan's price isn't published on its own pages
    • promo rate needs 2 years upfront and renews at ~$12
    • vendor pages disagree on whether ai credits are included
    • publishes a competing 'best hosts' ranking featuring itself
    advertisement
  4. 4

    Linode (Akamai)

    a proper one-click with real authentication — and an explicit statement that nobody will patch it afterwards.

    83/100

    verdictthe deployment is well built — two layers of auth and an option to disable root ssh — but akamai's refusal to own updates is a real cost on software whose worst incident came from unpatched instances.

    best for
    buyers who want an official one-click and will genuinely keep the instance updated themselves.
    price
    $12/mo
    pricing note
    linode 2 gb shared cpu: 1 vcpu / 50 gb / 2 tb transfer; globally uniform pricing
    free tier
    yes
    type
    vps
    ram at entry
    2 gb
    openclaw setup
    official one-click
    gateway security
    token + basic auth
    billing
    hourly or monthly

    the quick deploy app is thorough where it counts: access needs both a dashboard token and nginx basic-auth credentials, stored on the box for you, and the installer offers to disable root ssh login while always creating a limited sudo user. it deploys the gateway alongside the agent.

    then akamai says the quiet part out loud — it does not manage software or security updates for quick deploy apps after installation. that is honest, and it is also precisely the gap that put tens of thousands of openclaw instances on the public internet in february. an unattended install here ages badly.

    pricing matches digitalocean at $12 for 2 gb, uniform across regions, with a trial credit that expires rather than rolling over. the marketplace also carries an official ollama and open webui app, so the agent workload clearly has attention here.

    pros
    • +two independent auth layers out of the box
    • +installer offers to disable root ssh and creates a limited user
    • +official, vendor-documented quick deploy app
    • +uniform global pricing, broad region list
    cons
    • akamai explicitly does not patch quick deploy apps after install
    • no firewall rules or localhost binding documented
    • the memorable $5 nanode is 1 gb — below the practical floor
  5. 5

    Contabo

    the most hardware per euro and a free one-click add-on — attached to two vendor pages that flatly contradict each other on security.

    79/100

    verdictunbeatable specs and a genuinely free one-click add-on, undercut by the fact that contabo's own documentation cannot agree on whether your gateway is exposed.

    best for
    buyers who will verify the gateway binding themselves and want maximum headroom for the money.
    price
    €5.50/mo
    pricing note
    cloud vps 4: 4 vcpu / 8 gb / 100 gb; effective rate on a 24-month prepaid term
    free tier
    no
    type
    vps
    ram at entry
    8 gb
    openclaw setup
    free add-on
    gateway security
    vendor pages disagree
    billing
    24-mo prepay for the rate

    the hardware case is overwhelming: 4 vcpus and 8 gb for less than the price of a 2 gb droplet, with unlimited fair-use traffic, plus an openclaw add-on you can tick during provisioning at no extra cost. on paper this is the value pick of the category.

    then you read both of contabo's pages. its help centre states the control ui does not expose a public web interface and binds to 127.0.0.1 only. its own security guide says the gateway listens on port 18789 with no inherent access control, notes that openclaw 'can execute any shell command', and tells you to bind it to localhost yourself. those cannot both describe the same install, and we could not determine which is current.

    add the commitment pricing — €5.50 is the effective rate across twenty-four prepaid months, and the us price is a different number rather than a conversion — and this becomes a strong box you should personally verify before pointing it at your accounts.

    pros
    • +8 gb and 4 vcpus at a 2 gb price
    • +free openclaw add-on selectable at provisioning
    • +unlimited fair-use traffic, 9 regions including australia
    cons
    • vendor's own help centre and security blog contradict each other on gateway exposure
    • headline price needs 24 months prepaid
    • us pricing differs materially from the advertised eu rate
  6. 6

    Vultr

    a working marketplace app at $10 that also installs a second remote-access tool you didn't ask for.

    77/100

    verdictcheapest official one-click here, with credentials generated for you — but bundling code server onto an agent box adds attack surface on software that has already had an exposure problem.

    best for
    buyers who want an official one-click at the lowest us-provider price and will remove what they don't need.
    price
    $10/mo
    pricing note
    regular performance: 1 vcpu / 2 gb / 55 gb ssd; nvme tiers from $12/mo
    free tier
    no
    type
    vps
    ram at entry
    2 gb
    openclaw setup
    one-click
    gateway security
    generated credentials
    billing
    hourly or monthly

    vultr's docs describe a sensible-enough deployment: usernames and passwords auto-generated at provision time and shown once, covering the openclaw web interface, so nothing ships with a blank or default login.

    the bundled code server is the part to think about. a browser-accessible editor sitting next to an agent that can already run shell commands is a second door into the same machine, with its own password, on a box whose category is defined by a mass-exposure incident. it is convenient, and it is more surface than the job needs.

    beyond that: no firewall or localhost-binding detail is documented, $10 buys previous-generation cpus and plain ssd rather than nvme, and vultr's own marketplace page refused automated access when we tried to read it — the details above come from vultr's docs instead.

    pros
    • +official marketplace app at the lowest us entry price
    • +credentials auto-generated rather than defaulted
    • +wide global metro coverage
    cons
    • bundles code server, adding a second remote-access surface
    • no firewall or localhost-binding detail documented
    • cheapest tier is older cpus and non-nvme storage
  7. 7

    Klaus

    the most generous credit bundle of any managed host, from a company that at least tells you its name.

    75/100

    verdictthe credits alone account for most of the price, and the operator is identifiable — but it says nothing specific about the one thing this category turns on.

    best for
    teams who want an agent provisioned, monitored and pre-wired to integrations without touching a terminal.
    price
    $19/mo
    pricing note
    starter: includes $15/mo of ai credits plus $20 of orthogonal credits on a standard cloud instance
    free tier
    no
    type
    managed
    ram at entry
    unpublished
    openclaw setup
    one-click
    gateway security
    unspecified
    billing
    monthly

    the pitch is the whole stack managed: instances provisioned, updated and monitored by klaus, with orthogonal, agentmail and openrouter wired up before you arrive, so there is no gateway config and no oauth dance. at $19 including $15 of monthly ai credits, the hosting is close to free if you were going to spend the credits anyway.

    it is run by usebits inc, with published founder and support addresses. that is a lower bar than it should be, but in this category — where several competitors publish no company name at all — it counts for something real.

    the gap is security specificity. 'isolated + safe defaults' is the extent of it: nothing about how the control interface is reached, whether it is public, what authenticates it. it also publishes no server locations, which matters if your agent will hold eu personal data.

    pros
    • +$15/mo of ai credits included at the $19 tier
    • +fully managed: provisioned, updated and monitored
    • +integrations pre-wired — no gateway or oauth setup
    • +named operating company with public contacts
    cons
    • security description is generic with no gateway specifics
    • no published datacenter locations
    • no free tier or trial
  8. 8

    Kamatera

    $6, twenty-plus datacenters, hourly billing, no contract — and no openclaw anything.

    73/100

    verdictthe best geographic choice on the list at a fair price, with a free trial — but the openclaw page is marketing around a plain vps, so every security decision is yours.

    best for
    people who want the agent in a specific country and are happy installing it themselves.
    price
    $6/mo
    pricing note
    roughly 1 vcpu / 2 gb / 20 gb nvme; hourly or monthly, no minimum term
    free tier
    yes
    type
    vps
    ram at entry
    2 gb
    openclaw setup
    manual docker
    gateway security
    your responsibility
    billing
    hourly or monthly

    kamatera's advantage is reach and flexibility: twenty-plus datacenters from sydney to tel aviv to toronto, component-level control over cpu, ram and storage, hourly billing and no contract, plus a free trial. if the agent needs to sit in a particular jurisdiction, this is the easiest way to put it there.

    the openclaw page itself is a landing page for that vps rather than a product. installation is docker by hand, nothing is managed unless you buy the os-management add-on, and the vendor's security position is essentially that it stays out of your server — full root access, your firewall, your responsibility.

    that's an honest deal at $6 and this is an established infrastructure company rather than a 2026 arrival. it just offers nothing to the buyer who came here worried about defaults.

    pros
    • +20+ datacenters across five continents
    • +hourly billing, no minimum term, free trial
    • +component-level server configuration
    • +established infrastructure company
    cons
    • no one-click, no openclaw guide — manual docker
    • nothing managed unless you pay extra
    • all gateway hardening is your responsibility
  9. 9

    Hetzner

    the cheapest capable hardware anywhere, and the only major provider that has published nothing at all about this workload.

    71/100

    verdictstill the best hardware per euro in hosting, and in this category that buys you less than usual — there is no app, no guide, and no stated position on any of it.

    best for
    experienced linux users who already know how they want the gateway locked down.
    price
    €5.99/mo
    pricing note
    cx23: 2 vcpu / 4 gb / 40 gb ssd, ~20 tb traffic; hourly billing capped monthly
    free tier
    no
    type
    vps
    ram at entry
    4 gb
    openclaw setup
    manual docker
    gateway security
    your responsibility
    billing
    hourly or monthly

    the value is not in dispute. €5.99 for 2 vcpu, 4 gb and roughly 20 tb of traffic beats everything here, and hetzner doesn't sell a plan below what this workload wants, so the advertised price is the real one.

    everything else is absent. no openclaw marketplace app, no official tutorial, no security guidance, and no ai-agent apps of any kind in the one-click catalogue — it stops at docker, wordpress and gitlab. for a category where the top two entries win on documented defaults, publishing nothing is a real cost.

    one loose thread we could not close: third-party coverage claims hetzner ran an experimental programme offering free openclaw instances in tiers named after shellfish. hetzner's experiments site returned nothing readable, so we can neither confirm it exists nor tell you what it costs.

    pros
    • +4 gb and ~20 tb traffic for €5.99 — best value here
    • +no teaser tier: the advertised price is the honest one
    • +hourly billing capped at the monthly rate
    cons
    • no openclaw app, guide or security guidance of any kind
    • no ai-agent apps in the marketplace at all
    • reported free experimental programme is unverifiable
  10. 10

    xCloud

    a managed product with a sensible feature list and no published price for it.

    67/100

    verdictthe managed feature set is right — backups, ssl, firewall, monitoring — but a hosting product that won't print its own price is asking for trust it hasn't earned.

    best for
    existing xcloud customers adding an agent to infrastructure they already run.
    price
    unpublished
    pricing note
    no openclaw-specific price on the vendor's product or docs pages; a generic 'from $5/mo' appears in its docs for xcloud hosting broadly
    free tier
    no
    type
    managed
    ram at entry
    unpublished
    openclaw setup
    one-click
    gateway security
    unspecified
    billing
    unpublished

    the deployment is guided and the inclusions are the correct ones for this workload: full server backup, automatic ssl, a firewall and monitoring with alerts. you bring your own anthropic, openai or google credentials; nothing is bundled.

    the pricing is the problem, and it is self-inflicted. neither the openclaw product page nor the docs carry a price for it. the only figure on the vendor's own site is a general 'starts at $5/month' for xcloud hosting overall, which may or may not describe this. third-party coverage quotes $24/mo; we won't publish that as fact because xcloud doesn't.

    the firewall and monitoring are server-level. nothing states how the openclaw control interface itself is exposed or authenticated, which in this category is the question that matters.

    pros
    • +correct managed inclusions: backups, ssl, firewall, monitoring
    • +guided deployment with documented steps
    • +multi-product host rather than a single-page operation
    cons
    • no openclaw price published anywhere on its own site
    • no gateway-level security detail
    • no bundled model access
    • still described as new/beta in its own release notes
  11. 11

    OpenClaw Launch

    cheapest managed agent hosting anywhere, sold by an operator with no name, on a page it also uses to sell a different agent.

    64/100

    verdictgenuinely cheap with credits included and a free trial — but you cannot find out who runs it, and its own site prices openclaw and hermes identically, which tells you how specialised it isn't.

    best for
    a throwaway experiment you would not connect to anything you care about.
    price
    $6/mo
    pricing note
    lite: 1 vcpu / 2 gb / 10 gb, $3 the first month, includes $1/mo of openrouter credits
    free tier
    yes
    type
    managed
    ram at entry
    2 gb
    openclaw setup
    guided
    gateway security
    unspecified
    billing
    monthly

    as an experiment it's hard to argue with: $3 for the first month, daily backups, automatic https, small openrouter credits included, and the option to bring your own key or an existing subscription instead. the pro tier at $20 adds 4 gb and $10 of credits.

    the operator publishes no company name, no address, no founders. its openclaw pricing and specs are reused almost verbatim on its hermes agent page — the site states outright that the two frameworks cost the same — which is a templated reseller pattern rather than a product built around either.

    for openclaw specifically that matters more than usual. this agent holds message history, oauth tokens and api keys, and can execute shell commands. 'fully private and encrypted' is the entire security disclosure, and there is nobody named to hold to it.

    pros
    • +lowest entry price of any managed option, $3 first month
    • +openrouter credits bundled at every tier
    • +free trial without a card
    • +daily backups and automatic https
    cons
    • no company name, address or team published
    • identical plans and pricing reused for a different agent product
    • security disclosure is one marketing phrase
    • no datacenter locations published
  12. 12

    Oracle Cloud Always Free

    free forever, if you can get capacity, keep it busy, and secure it using a guide oracle didn't write.

    62/100

    verdictthe only genuinely free option and the least supported one — oracle publishes nothing about this workload, so the best available guidance comes from the openclaw project itself.

    best for
    tinkerers who treat the setup as the hobby and won't mind rebuilding it.
    price
    $0
    pricing note
    always free ampere a1: the equivalent of 2 ocpus and 12 gb within monthly hour allowances
    free tier
    yes
    type
    free cloud
    ram at entry
    up to 12 gb
    openclaw setup
    manual docker
    gateway security
    your responsibility
    billing
    free within limits

    the allowance is real and generous: oracle's own docs put always free ampere at the equivalent of 2 ocpus and 12 gb — not the 4 ocpu / 24 gb figure repeated everywhere else — indefinitely, with no paid upgrade required. that is more memory than any paid entry plan here.

    oracle offers nothing for this workload: no marketplace app, no tutorial, no security guidance. the useful instructions come from the openclaw project's own guide for oracle's free tier, which recommends binding the gateway to loopback, using token auth, and locking the network security list down to tailscale traffic with port 22 blocked entirely. that is sound advice, and it is not oracle's.

    two structural risks remain. always-free arm capacity is chronically oversubscribed and provisioning is a lottery tied to the home region you picked at signup. and oracle reclaims instances whose cpu, network and memory all sit under 20% utilisation over a rolling week — a personal agent waiting for messages is exactly that shape.

    pros
    • +genuinely free indefinitely, per oracle's own terms
    • +12 gb ceiling beats every paid entry plan here
    • +the openclaw project publishes a hardening guide for this exact setup
    cons
    • oracle publishes no app, tutorial or security guidance
    • arm capacity is a provisioning lottery, locked to your home region
    • idle instances get reclaimed — quiet agents fit the definition
    • every hardening step is manual

how this ranking was made

gateway defaults are the first-class fact on every entry, verified from each vendor's own documentation rather than its marketing. what we looked for: does the control interface bind to localhost or to every interface, is there authentication before first access, is there a device-pairing or token step, and does the vendor front it with tls.

where a vendor's own pages contradict each other we publish both. contabo's help centre states the control ui binds to 127.0.0.1 by default; contabo's own security blog says the gateway listens on port 18789 with no inherent access control and that openclaw 'can execute any shell command'. we are not able to tell you which is true, and neither of those pages knows about the other.

prices are the vendor's own published figures, checked on the review date, quoted at the cheapest plan with at least 2 gb of ram. where a headline rate requires a prepaid term — contabo's 24 months, hostinger's 2 years, ovhcloud's 12 — the entry says so and gives the no-commitment price where one is published.

'one-click' means a listing in the provider's own marketplace or a documented add-on in its own control panel. a blog tutorial is not a one-click, and entries say which one a vendor actually has. we also note who built the listing: digitalocean's is maintained in-house, which is not the same as a community package.

who patches it afterwards is treated as a ranking factor, not a footnote. akamai states plainly that it does not manage software or security updates for quick deploy apps once installed. for software with this exposure history, an unpatched instance is the whole problem.

one vendor, myclaw.ai, is not ranked. its site returned 403 to every attempt to read its own pricing and product pages, so there is no figure or claim on it we could verify. we would rather leave a gap than repeat what a search snippet said.

model costs are excluded from the ranking, since the same openrouter or api bill follows you to any host. bundled credits are described as a convenience and not scored.

our general methodology and disclosures →
was this useful?