Back to guides

Run your own AI agent on a $4.73 VPS: how much RAM OpenClaw and Hermes really need

How much RAM OpenClaw and Hermes Agent need on a VPS: measured numbers, plans from $4.73 a month, install steps from the docs and a security checklist.

A server for a personal AI agent starts at $4.73 a month: that is the cheapest 2 vCPU / 4 GB RAM plan in our catalog. The hardware is not what gets expensive. Model tokens and setup mistakes are.

Agent names change fast. OpenClaw peaked in the first quarter of 2026, and Hermes Agent took over the conversation in the summer. Sizing does not change with the name. It depends on what the agent does on the box. So the numbers below are tied to workload, and the commands cover both agents.

Plan prices below are catalog prices as of Aug 30, 2026, taken from the providers' official sites. Commands are checked against the docs on Oct 11, 2026.

What the agent needs: measured vs claimed

First, an honest split. The official OpenClaw docs give no RAM figures. They state the Node requirement (24.16+ or 26.1+) and describe how the Linux kernel picks processes to kill when memory runs out (exit code 137), but not gigabytes. The Hermes Agent install page does not list hardware requirements either, only Python 3.14, which its installer manages.

The only figures with actual measurements we found are in a Habr write-up: the author ran Hermes on a VPS with 1 vCPU and 2 GB RAM and watched what it used. Everything else is a claim without measurements.

Scroll the table to the right →

WhatNumberStatus
One Hermes processabout 210 MB RAMmeasured by the author
Headless Chrome600+ MB, depends on the sitemeasured by the author
faster-whisper, base model540 MBmeasured by the author
CPU under Chrome or whisperup to 100% of one vCPU, 1-2% idlemeasured by the author
Disk, clean Ubuntu with the agent10-15 GBmeasured by the author
OpenClaw process300-500 MB in one guide, about 1.5 GB in anotherclaimed, no measurements
"2 vCPU, 4 GB, 20-40 GB SSD"for an agent with a cloud model and a browserrepeated across several guides

The arithmetic is simple. A 210 MB agent process plus 600 MB of Chrome is already over 800 MB before the OS, a second tab and any spikes. If the OpenClaw process is near the upper claimed figure, 2 GB runs out fast. The author of the measurements says outright that 1 GB is not enough even for his setup.

That gives three profiles:

  • Minimum, 1 vCPU / 2 GB. An agent in a messenger, a cloud model, no browser, no voice transcription. Add swap.
  • Comfortable, 2 vCPU / 4 GB. The agent plus a headless browser, cron jobs, a couple of parallel sessions.
  • Headroom, 4 vCPU / 8 GB. Several users, voice, heavy pages, multiple browser sessions.

Disk: the plans below are filtered to at least 20 GB, but a clean install already takes 10-15 GB. If you can, take 40 GB or more.

What the server costs: catalog prices as of Aug 30, 2026

From the VPS catalog we took each provider's cheapest plan that fits the profile (the required vCPU and RAM, at least 20 GB of disk), then calculated the minimum and median across providers.

Scroll the table to the right →

ProfilevCPU / RAMProvidersCheapest, $/moMedian, $/moMedian without Russian servers, $/mo
Minimum, no browser1 / 2 GB242.956.476.88
Comfortable, agent + browser2 / 4 GB244.7311.3113.61
Headroom4 / 8 GB237.5322.9125.02
Small local model4 / 16 GB2115.3737.9037.77

The three cheapest plans in each profile, by provider:

Scroll the table to the right →

ProfileProvider and planSpecLocation$/mo
1 / 2 GBXorek DE-R9-2 (249 ₽)1 vCPU, 2 GB, 30 GB NVMeGermany, Finland, Netherlands2.95
Selectel VDS 1-2-25 (250 ₽)1 vCPU, 2 GB, 25 GB NVMeRussia2.96
netcup VPS nano G11s (€3.08)2 vCPU, 2 GB, 60 GB SSDGermany3.53
2 / 4 GBXorek DE-R9-4 (399 ₽)2 vCPU, 4 GB, 60 GB NVMeGermany, Finland, Netherlands4.73
Firstbyte MSK-highmem-KVM-SAS-2 (439 ₽)2 vCPU, 4 GB, 60 GB SAS+SSDRussia5.20
OVHcloud NL VPS-1 (€4.61)2 vCPU, 4 GB, 40 GB NVMeNetherlands5.28
4 / 8 GBHOSTKEY vm.v2-mini (€6.57)4 vCPU, 8 GB, 120 GB NVMeNetherlands, Finland, Italy7.53
Xorek DE-R9-8 (749 ₽)4 vCPU, 8 GB, 120 GB NVMeGermany, Finland, Netherlands8.87
netcup VPS 1000 ARM G11 (€7.77)6 vCPU, 8 GB, 256 GB NVMeGermany, Austria, US8.91
4 / 16 GBnetcup VPS 2000 ARM G11 (€13.41)10 vCPU, 16 GB, 512 GB NVMeGermany, Austria, US15.37
HOSTKEY vm.v2-medium (€14)8 vCPU, 16 GB, 160 GB NVMeNetherlands, Finland, Italy16.05
Xorek DE-R9-16 (1,399 ₽)8 vCPU, 16 GB, 240 GB NVMeGermany, Finland, Netherlands16.58

What to keep in mind:

  • None of the twelve plans has PROMO in its name. If you see a plan with PROMO in the name at checkout, treat the price as temporary.
  • Dollars are the catalog's conversion, not the currency you pay in. The netcup ARM G11 plans run on ARM processors: check that your agent and its dependencies run on ARM.
  • Cheapest does not mean best. We did not measure network speed, support or stability. Location matters for latency to the APIs you use, data residency and payment convenience, and nothing else.

For how we calculate prices and how many plans the catalog holds, see the VPS price overview. If you need a server for a bot or a set of cron jobs without an agent, see the VPS for bots checklist.

What an agent really costs per month

The server is $5-10. The main expense is the model. I am not quoting prices because they depend on the model, the context size and how many times the agent calls the browser and tools. Check current prices on the model provider's official pages, for example Anthropic and OpenAI.

For a sense of scale, one real case. The author of a Habr post put $40 on OpenRouter and burned through it in under three weeks of "lazy use" of OpenClaw. His final table adds up to $56.59. That is one story, not an average, but it shows why you cap the token budget before you start.

What to do:

  • Top up a prepaid balance in small amounts, or set a hard monthly limit in the provider's console.
  • Use a cheap model for routine work and turn on the expensive one for hard tasks.
  • Watch for loops: an agent that is stuck and repeating steps burns tokens for nothing.

Installing OpenClaw

Prepare the server first. This is standard Linux hygiene, not steps from the agent docs. Examples for Ubuntu or Debian, as root, once:

adduser agent
usermod -aG sudo agent
rsync --archive --chown=agent:agent ~/.ssh /home/agent
ufw default deny incoming
ufw default allow outgoing
ufw allow OpenSSH
ufw enable

Then disable password login and root login over SSH (in /etc/ssh/sshd_config or a file in sshd_config.d: PermitRootLogin no and PasswordAuthentication no), but first make sure you can log in as agent with your key. Otherwise you lock yourself out.

From here on, do everything as the agent user, not as root.

Install. According to the install docs you need Node 24.16+ or 26.1+. The installer sets up Node itself if it is missing.

curl -fsSL https://openclaw.ai/install.sh | bash

The installer starts the setup wizard. To run the same wizard by hand, together with installing the systemd service:

openclaw onboard --install-daemon

The wizard can reuse an existing Claude Code or Codex CLI login, or ask for a provider key. The rules for using subscriptions inside third-party agents have changed several times, so check the provider's current terms before relying on one. An API key is the safest route.

Verify:

openclaw --version
openclaw doctor
openclaw gateway status

Per the docs, the Gateway listens on port 18789 and by default is bound to loopback, that is 127.0.0.1.

Keep the service alive after you log out. OpenClaw installs a systemd user service. The docs say to enable lingering:

sudo loginctl enable-linger $(whoami)

For small servers. The VPS page recommends Node's compile cache and restarting the Gateway in-process:

export NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache
mkdir -p /var/tmp/openclaw-compile-cache
export OPENCLAW_NO_RESPAWN=1

The docs add these lines to ~/.bashrc. For the systemd service, the same variables go through systemctl --user edit openclaw-gateway.service.

Reaching the dashboard. We do not open port 18789 to the internet. Two options from the docs:

An SSH tunnel from your own computer:

ssh -N -L 18789:127.0.0.1:18789 agent@YOUR-SERVER-IP

While the tunnel is open, the Control UI is reachable from your computer. The openclaw dashboard command gives you the link.

Or Tailscale Serve: the Gateway stays on loopback and Tailscale lets in only your own devices. You need the tailscale CLI installed and logged in. Config:

{
  gateway: {
    bind: "loopback",
    tailscale: { mode: "serve" },
  },
}

Installing Hermes Agent

According to the Hermes docs, the installer sets up the required Python 3.14 itself. All you need is Git, curl, tar and a SHA-256 utility.

curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash

Reload your shell (source ~/.bashrc) and run the setup:

hermes setup
hermes model
hermes gateway setup
hermes doctor

hermes setup walks through the configuration, hermes model picks the provider and model, hermes gateway setup connects messaging platforms, and hermes doctor reports what is missing. Data and config live in ~/.hermes/.

Service. For the gateway on a server:

hermes gateway install
sudo loginctl enable-linger $USER
hermes gateway status
journalctl --user -u hermes-gateway -f

The docs also offer a system service (sudo hermes gateway install --system) for when the service must come up at boot without lingering. I would start with the user service: simpler and with fewer privileges.

Limit who can talk to the agent. With no allowlist, Hermes denies everyone by default. Set IDs through a variable such as TELEGRAM_ALLOWED_USERS (numeric IDs, comma-separated), or use a pairing code: hermes pairing approve <platform> <code>.

Security checklist

The agent reads mail, websites and files, and it runs commands. Anything it reads can carry instructions aimed at it. The OpenClaw prompt-injection docs say plainly: treat links, attachments and pasted text as hostile by default. A better model reduces the risk but does not remove it.

  1. Ports. OpenClaw is bound to loopback by default. The docs say the lan, tailnet and custom modes need authentication (a token or password) and a real firewall, and that Tailscale Serve is preferred over an open LAN port. Check what the server actually listens on with ss -tlnp. Only SSH should be visible from outside.
  2. Docker bypasses ufw. Ports published by Docker skip the ufw INPUT rules. The OpenClaw docs have a dedicated section with rules for the DOCKER-USER chain. If you run the agent in Docker, do not publish ports to the outside.
  3. A separate non-root user. The agent runs commands as its own user. The Hermes docs warn that the terminal tool runs as the same OS user, and that file write guards are an extra layer, not a boundary. Do not give that user passwordless sudo.
  4. SSH keys only. Root login and password login are off.
  5. API keys in a file with permissions. Hermes keeps keys in ~/.hermes/.env, with chmod 600 ~/.hermes/.env. OpenClaw keeps state in ~/.openclaw; the docs call for 700 on the directory and 600 on openclaw.json, and openclaw doctor warns about loose permissions. Never commit .env to Git.
  6. Who can message the agent. In most OpenClaw channels, unknown senders get a pairing code, and groups work by allowlist and mention. Hermes has an allowlist or pairing. Do not turn on the "allow everyone" modes.
  7. Command approval. In Hermes, approvals.mode defaults to smart; off disables all prompts. approvals.deny blocks commands by pattern, but the docs call it a policy, not a sandbox. For real isolation use a container backend. In the OpenClaw hardened baseline, exec is set to deny with approval always asked.
  8. Audit. openclaw security audit finds drift from the safe defaults.
  9. Skills and plugins are code. Install only the ones you have read.
  10. Updates. Keep the agent (hermes update) and the system updated.
  11. Browser profile. Do not connect the agent to your personal Chrome profile with logged-in sessions. The OpenClaw docs say the model can then reach those accounts. Use a separate profile.
  12. Backups. Agent state contains tokens and chat history. Decide on purpose where it is copied, and encrypt it.

This is not theory. In September 2026 the OpenClaw repository published a batch of advisories, two of them rated High: exec approvals could outlive the working directory they were granted for, and the WhatsApp login tool could be reached in non-owner turns. In spring 2026 OpenClaw fixed CVE-2026-33579, rated CVSS 9.9: a user allowed to pair devices could approve a request for admin scopes. It is fixed in 2026.3.28, so update old installs. Researchers also reported malicious skills in the ClawHub catalog (the campaign was named ClawHavoc): see Aviatrix's write-up. Sources disagree on how many skills were infected, from hundreds to over a thousand, so I do not give a figure.

When the agent's browser gets blocked

The agent goes to a site from a data center and gets a captcha or an error. That is normal: data center IP ranges have a different reputation from home ones. But the IP is only one signal. Sites also look at the browser fingerprint, the TLS fingerprint and behavior. Changing the IP alone often changes nothing.

A proxy helps when:

  • the site blocks data center ranges specifically and answers regular visitors normally;
  • automated access is allowed (public pages, your own site, a partner API with no bot restrictions);
  • request volume is low and you stay within rate limits.

In those cases residential proxies fit. Mobile proxies cost more and are needed less often, mostly for services built around mobile traffic.

A proxy will not help when:

  • the site forbids automation in its terms of use or in robots.txt. Respect that: a proxy here is not a fix, it is a violation;
  • the block is tied to an account, a browser fingerprint or behavior;
  • the plan involves multiple accounts or getting around a service's restrictions: do not do that;
  • the site has an API or a data export that is simpler and more honest.

How to plug in a proxy. There is an honest gap here. The OpenClaw browser configuration docs have no dedicated proxy option, and the extraArgs setting for launching Chromium is described without a proxy example. In the Hermes docs the only proxy mentioned is BROWSERBASE_PROXIES for the cloud Browserbase backend, and there is no general HTTP proxy setting. So I do not describe how to attach a proxy to the agent's built-in browser: check the current docs or the repository for your version. For your own scripts and tools built on Playwright, the official docs show this setting:

const browser = await chromium.launch({
  proxy: {
    server: 'http://myproxy.com:3128',
    username: 'usr',
    password: 'pwd'
  }
});

Before you buy a proxy, check it with our guide to testing a proxy.

Local LLM on a VPS: a reality check

It is tempting to drop API costs and run a model on the same server. Consider the LearnWithHasan measurements (August 2026): the author rented six DigitalOcean servers and measured single-user generation speed on Ollama.

Scroll the table to the right →

ServerPrice per monthllama3.1 8B, tok/sllama3.2 3B, tok/s
4 shared vCPU, 8 GB$482.85-7
8 shared vCPU, 16 GB$965.3-5.4not reported
8 dedicated vCPU, 16 GB$1686.812-15
RTX 4000 Ada GPU, 20 GB$0.76 per hour63not measured

Takeaways:

  • On a CPU VPS an 8B model produces 2.8 to 6.8 tokens per second. That is tolerable for chat and very slow for an agent that takes dozens of tool steps.
  • Hosting sellers promise more (5-15 tok/s for a 7B model on a modern 8-core CPU), but those are claims without independent measurement, and they sit above the measured figures.
  • An 8B model at 4-bit quantization takes about 4.9 GB (per the same measurements). So 8 GB is the lower bound, and 16 GB is the realistic minimum to leave room for the agent and the OS. In the catalog that is 4 vCPU and 8 GB from $7.53, and 16 GB from $15.37 a month.
  • A GPU is many times faster, but $0.76 an hour running around the clock comes to about $555 a month.

Verdict: for a personal agent on a VPS, use an API model and keep local models for private tasks and experiments. If you do run Ollama, do not expose its port to the internet.

When you do not need a VPS

There is a free alternative. On Oct 10, 2026, Talorys collected about 300 points on Hacker News: a personal AI assistant that runs in your own Cloudflare account on the free tier, with chat, memory, tasks, notes and reminders. The author runs no servers or databases. The limits are set by Cloudflare and can change.

The project description does not mention browser control, access to files or arbitrary tools. A VPS stays the better choice when you need:

  • the agent running around the clock;
  • control of a browser;
  • reading and writing files on the server;
  • local tools, scripts and cron.

If all you need is an assistant with notes and reminders, you do not need a server.

FAQ

How much RAM does OpenClaw need? The official docs give no figure. Few real measurements exist; from those and the guides, the minimum is 2 GB without a browser, and 4 GB and 2 vCPU is comfortable with one. One measurement for Hermes: about 210 MB per process, headless Chrome 600+ MB.

Can I run an agent on 1 GB? The author of the measurements says 1 GB is not enough. If you must, add swap, skip the browser and voice, and watch for exit 137: that is how the kernel reports that a process was killed for lack of memory.

Which is lighter, OpenClaw or Hermes? We found no fair comparison on the same server. The 210 MB figure is for Hermes and was measured; the OpenClaw figures are claims without measurements. They cannot be compared directly.

Do I need a GPU? No, if the model runs through an API. A GPU only matters for local models, and it costs orders of magnitude more than a regular VPS.

Is it safe to expose the dashboard to the internet? No. Use an SSH tunnel or Tailscale. If you truly need external access, do it only with a token or password, a real firewall and an IP restriction, as the OpenClaw docs say.

How much does an agent cost per month in total? A server from $4.73 for 2 vCPU and 4 GB, plus model tokens, which depend on the model and your usage. Set a limit in the model provider's console.

All the servers for comparison are in the VPS catalog.

Sources

Commands checked against the docs on Oct 11, 2026.

Plan prices are from the researched.xyz catalog as of Aug 30, 2026, converted to dollars at the catalog rate. Check the price on the provider's site before you pay.