VPS for AI Agents in 2026: Real Specs, Verified Prices, Real Risks
Verified October 2026 prices for the boxes that actually run OpenClaw, the Hermes agent, and Claude Code, the official spec floors, the 2026 security lessons, and the honest DIY-vs-managed math.
The best VPS for AI agents in 2026 is a plain 2 vCPU / 4 GB Linux box: Vultr at $20/mo and DigitalOcean at $24/mo are the safe DIY picks now that Hetzner's cheap CX line is unorderable, and Oracle's free ARM tier is the zero-dollar gamble. The agents themselves (OpenClaw, Hermes agent, Claude Code) cost nothing to install, so the real bill is the box plus your model usage. And if you would rather skip server admin entirely, Agent37 runs the same agents always-on from $3.99/mo, with a free sleeping agent to try first.
This guide exists because the pages ranking for this search disagree with each other. One quotes Hetzner "from $5.99", another lists a 4 GB plan at over 14 euros, and both are technically citing the same provider. Prices below were checked against official pricing pages and APIs on October 7, 2026, and every spec claim cites the project's own docs, linked in the table below.
What an AI agent actually needs from a VPS
An AI agent is not a model. OpenClaw, Hermes agent, Claude Code, and Codex are harnesses: they run tools, hold memory, and talk to channels, while the actual model runs in Anthropic's, OpenAI's, or another provider's data center. That means your server needs no GPU, modest CPU, and enough RAM to keep a Node or Python process plus its tools alive.
Here is what the projects themselves publish, not what hosting blogs guess:
Two honest readings of that table. First, OpenClaw's official floor really is 1 GB: its own DigitalOcean guide deploys on a $6 1 GB droplet and tells you to add swap. Second, the floor is not the target. Community troubleshooting guides are full of OOM-killed gateways on 1-2 GB boxes once browser automation, Docker, media handling, or a second channel joins the party, and the moment Claude Code enters the picture you inherit its official 4 GB requirement anyway.
So the sensible shape to shop for is 2 vCPU, 4 GB RAM, 40-80 GB disk. It runs any one of these agents with headroom, and it is the shape every price below is quoted at.
The best VPS for AI agents in 2026, with verified October prices
Provider
Shape
Price (Oct 2026)
The catch
Vultr
2 vCPU / 4 GB / 80 GB
$20/mo
One price everywhere except São Paulo ($30)
DigitalOcean
2 vCPU / 4 GB / 80 GB
$24/mo
Premium NVMe variant is $28
Linode (Akamai)
2 vCPU / 4 GB / 80 GB
$24/mo
Near-identical to DO
AWS Lightsail
2 vCPU / 4 GB / 80 GB
$24/mo
Fine if you live in AWS already
Hetzner CPX22
2 vCPU / 4 GB / 80 GB
EUR 19.49 + EUR 0.50 IPv4
Germany/Finland price; Singapore EUR 26.49; US closest is 3 vCPU / 4 GB at $37.49
Contabo Cloud VPS 4
4 vCPU / 8 GB / 100 GB
EUR 5.50 (USD 6.60 on its US site)
Non-EU regions add a location surcharge
Oracle Always Free
2 OCPU / 12 GB ARM
$0
Capacity lottery; idle instances get reclaimed
Vultr is the value pick. The 2 vCPU / 4 GB cloud compute instance is $20/mo with the same price in almost all of its roughly 30 regions (São Paulo is the one exception at $30), hourly billing, and no term commitment. Boring, which is what you want from a box whose whole job is staying up.
DigitalOcean, Linode, and Lightsail all land at $24/mo for the same shape. Pick whichever dashboard you already know; the differences at this size are cosmetic. OpenClaw's official install docs even walk through DigitalOcean specifically.
Hetzner needs the honest update nobody else is publishing. The famous cheap plans (CX23 at EUR 5.49, CAX11 at EUR 5.99) are still listed but flagged "currently not available" across the board as of October 2026, and they were EU-only anyway. What you can actually order is the CPX line: CPX22 at EUR 19.49/mo plus EUR 0.50 for an IPv4 in Germany or Finland. In the US regions there is no 2 vCPU / 4 GB size at all; the closest is 3 vCPU / 4 GB at $37.49/mo. Any listicle still recommending Hetzner "from $5" is quoting a plan you cannot buy. We cover the EU math in detail in our Hetzner guide for the Hermes agent.
Contabo is the budget outlier: 4 vCPU / 8 GB / 100 GB for EUR 5.50/mo (USD 6.60 on its US site), with no setup fee and discounts for longer terms (down to about EUR 4.40 on a 24-month commitment). The asterisks: non-EU regions add a monthly location surcharge at checkout, and Contabo's own pages disagree on whether EUR 5.50 is the month-to-month rate or the 24-month effective rate, so confirm the total in the order flow. Interesting detail for this audience: Contabo now ships one-click OpenClaw and "Hermes AI" images, so they clearly see the same search you just made.
Oracle Cloud Always Free gives you up to 2 ARM OCPUs and 12 GB RAM at $0, which on paper beats everything here. In practice it is a gamble twice over: popular home regions regularly report no free ARM capacity, and Oracle's published policy reclaims Always Free instances whose 7-day CPU, network, and memory utilization all sit under 20 percent. A mostly-idle personal agent is exactly that profile. Treat it as a bonus if you win it, not a plan.
Every agent in this guide is free to install, and two are genuinely open source: OpenClaw is stewarded by an independent 501(c)(3) foundation with no paid version, no hosted tier, and no token, and the Hermes agent is MIT-licensed by Nous Research. So the honest cost of running one is:
The box: $20-24/mo mainstream, or Contabo's EUR 5.50-and-under budget class with its checkout caveats.
The model: bring-your-own API keys, so this scales with usage. A light personal agent can run on a few dollars of API spend a month; heavy automation costs more.
One gotcha: Claude Code is free to install but requires a paid Anthropic plan (Pro and up) or API billing. There is no free way to run it, on any VPS.
Your time: updates, disk pressure, the firewall, and reading security advisories. That line item is real, as the next section shows.
A useful benchmark for comparison shopping: an always-on 2 vCPU / 4 GB agent box costs $240-288 per year DIY at mainstream providers. Hold that number against the managed options below, and against our cheapest sandbox for AI agents comparison if you are evaluating the API route.
Security is where DIY agent hosting goes wrong
This is the section the listicles skip, and it is the strongest argument for either doing a VPS properly or not doing one at all.
In early 2026, security firm Hunt.io found over 17,500 OpenClaw-family gateways exposed to the public internet, nearly half of them on the default port 18789. Around the same time, CVE-2026-25253 demonstrated a one-click remote code execution against OpenClaw installs: a malicious link could exfiltrate the gateway's auth token even when the gateway was bound to loopback, because the victim's own browser made the connection. It was patched within days (clawdbot 2026.1.29), but the lesson stands: an agent with shell access, your API keys, and your messaging accounts is a high-value target.
The June 2026 Hermes agent hardening tells the same story from the other side: after scanners started fingerprinting dashboards launched with --insecure on public interfaces, the flag was made a no-op. Today a Hermes dashboard bound to any non-loopback address refuses to start until real authentication is configured.
If you run the box yourself, the baseline is:
Keep the gateway and dashboard on loopback. OpenClaw's docs say it plainly: never expose the gateway unauthenticated on 0.0.0.0. Reach it over Tailscale Serve or an SSH tunnel instead of opening the port.
Watch the Docker exception. Inside a container, OpenClaw's effective default bind resolves to 0.0.0.0 for port forwarding. Containerized installs need explicit config plus default-deny firewall rules on the DOCKER-USER chain.
Default-deny inbound. The only ports a stranger should see are SSH (keys only, no passwords) and, if you run one, a reverse proxy.
Scope the credentials. Your .env holds model keys and channel tokens; chmod 600 it, and prefer per-service tokens you can revoke.
Update on a schedule. Both issues above were fixed fast. The exposed instances that got hunted were the ones nobody patched.
None of this is hard, but all of it is recurring. Decide up front whether you want that recurring job.
When a VPS is the wrong tool
A VPS is the right call when you want root, a custom stack, several agents sharing one box you fully control, or a specific jurisdiction for your data. If what you actually want is "my agent, always on, without the admin work", managed hosting is the cheaper path once your time enters the math.
That is the product we run. Agent37 hosts OpenClaw, the Hermes agent, Claude Code, Codex, OpenCode, and Grok on managed instances with a task board, a full web terminal, a file browser, and scheduled jobs. One personal agent is free to start: no card, it sleeps after 15 minutes idle and wakes when you message it, with $0.20 of model credit included. Always-on starts at $3.99/mo with your own API keys, which undercuts every paid DIY option in the table above. Runtime and security patches roll out automatically. The honest trade-off at these prices: support is community-first, not a 24/7 human queue.
Builders shipping agents to their own customers skip the per-box thinking entirely: the Agent37 Cloud API provisions an isolated always-on instance per user at metered rates, with a 2 vCPU / 4 GB instance at $4.76 per month of continuous running, dropping to disk-only pennies while it sleeps. Add a card and you get a $5 starter credit, enough to run the entry shape for about a month.
FAQ
Do AI agents need a GPU VPS?
No. Agents like OpenClaw, the Hermes agent, and Claude Code call hosted models over an API, so the heavy compute happens on the provider's hardware, not yours. A GPU VPS only matters if you plan to run local model inference, which is a different (and much more expensive) purchase than agent hosting.
How much RAM does a VPS need to run an AI agent?
Officially: OpenClaw says 1 GB minimum with 2 GB+ recommended, Claude Code says 4 GB+, and the Hermes agent publishes no minimum. Practically, buy 4 GB. It covers every harness's stated floor, survives browser automation and multi-channel setups that OOM-kill smaller boxes, and only costs a few dollars more than 2 GB.
Can I run an AI agent on a free VPS?
Sometimes. Oracle's Always Free ARM tier (up to 2 OCPU / 12 GB) is the only serious free VPS, but capacity is scarce in popular regions and Oracle reclaims instances that idle below its utilization thresholds for a week. If the goal is simply a free way to try an agent, a free hosted agent on Agent37 avoids the capacity lottery: it sleeps when idle and wakes when you message it (only an agent left asleep a full 30 days is removed, with an email warning a week before).
How do I keep an AI agent running 24/7 on a VPS?
Run it as a service, not a shell session: a systemd unit or Docker with a restart policy, so the agent survives reboots and crashes. OpenClaw's official Docker and DigitalOcean guides cover both patterns. Then monitor it; an agent that silently died three days ago is the classic DIY failure mode.
Can I run several AI agents on one VPS?
Yes, if the RAM adds up: budget roughly 1-2 GB per gateway-style agent and 4 GB whenever Claude Code is one of them, and isolate each agent's credentials. One warning: agents for different clients on one shared box is a liability pattern. If you are hosting agents for customers, per-customer isolated instances (what the Agent37 Cloud API does by default) is the structure that scales safely.
Founder at Agent37, which runs managed hosting for OpenClaw and Hermes agents for 1,000+ users. Writes about what actually breaks when you leave an AI agent running.