PLATFORM CAPABILITIES

Infrastructure that stays out of your way.

OpenClaw is powerful software. Hosting it for customers needs careful isolation, predictable resources, and operations that recover cleanly.

01 / PLATFORM

A gateway per customer

Each OpenClaw customer runs in an independent Docker container. Separate config, filesystem, credentials, and resource allocation.

02 / PLATFORM

State that persists

A dedicated volume follows the instance through restarts and container rebuilds. Your agent keeps its configuration and local state.

03 / PLATFORM

Queue-driven provisioning

Payment webhooks create durable, retryable jobs. Requests return quickly while workers select capacity and provision in the background.

04 / PLATFORM

Plans that can change

Operators create plans from the admin console. Resource limits are copied into each purchase so later edits do not alter existing instances.

05 / PLATFORM

Health-aware placement

Unhealthy and maintenance nodes are removed from placement. A reconciler compares control-plane state with Docker and reports drift.

06 / PLATFORM

Private per-instance networks

Every gateway has its own bridge network. The trusted reverse proxy joins only the customer network it needs to route.

SECURITY POSTURE

Isolation is a deployment property.

Customers never receive host access or a Docker socket. Worker nodes use mutual TLS, containers run with dropped Linux capabilities and no-new-privileges, and provider credentials are encrypted in the control-plane database.

Tenant-scoped access

Customer APIs filter every customer-owned record through the authenticated tenant.

Narrow network access

Only the platform reverse proxy can reach the gateway port; container ports are never published to the host.

Auditable operations

Administrative node changes and provisioning attempts leave timestamped records.

READY WHEN YOU ARE

Start with one instance.

See plans