---
title: "Deploy OpenClaw Private Gateway"
description: "Private OpenClaw Gateway, reachable only over your Tailscale tailnet"
category: "AI/ML"
url: https://railway.com/deploy/openclaw-private-gateway
---

# Deploy OpenClaw Private Gateway

Private OpenClaw Gateway, reachable only over your Tailscale tailnet

**[Deploy OpenClaw Private Gateway on Railway](https://railway.com/template/openclaw-private-gateway)**

Machine-readable deploy manifest (JSON, validated by TemplateCI): https://railway.com/deploy/openclaw-private-gateway/manifest.json

- **Creator:** Steve Kinney's Projects
- **Category:** AI/ML

## Template content

### openclaw

- **Source:** https://github.com/stevekinney/openclaw-railway-template
- **Health check:** /startupz

### tailscale

- **Source:** https://github.com/stevekinney/openclaw-railway-template
- **Health check:** /healthz

## Documentation

# Deploy and Host OpenClaw Private Gateway on Railway

OpenClaw Private Gateway runs your own [OpenClaw](https://openclaw.ai) Gateway on Railway, reachable only from your Tailscale tailnet. There is no public domain, no setup web server, and no proxy in front of the Gateway. The macOS app, the dashboard, and your phone connect to it privately over Tailscale.

## About Hosting OpenClaw Private Gateway

This template starts two services in one project:

- **openclaw** runs the official OpenClaw image (a pinned release) with the Gateway as its only process. All state lives on a volume at `/data`. Token authentication and device pairing are always on, and a fresh deployment passes `openclaw security audit` with no findings.
- **tailscale** runs the official Tailscale container in userspace mode, with no extra privileges. It joins your tailnet as `openclaw` and forwards raw TCP to the Gateway over Railway's private network, with HTTPS from your tailnet's certificate.

Before you deploy, turn on **MagicDNS** and **HTTPS certificates** in the Tailscale admin console, note your tailnet's DNS name (for example `tail1234.ts.net`), and generate an auth key (not reusable, not ephemeral). The template asks for:

| Variable | Value |
| --- | --- |
| `OPENCLAW_PUBLIC_ORIGIN` | `https://openclaw..ts.net` |
| `TS_AUTHKEY` | your Tailscale auth key |

`OPENCLAW_GATEWAY_TOKEN` is generated for you; copy it from the openclaw service's Variables to connect clients. After deploying, add your model provider's API key, run one onboarding command over `railway ssh`, and pair the macOS app. The [Quickstart](https://github.com/stevekinney/openclaw-railway-template/blob/main/docs/QUICKSTART.md) has every command.

## Common Use Cases

- A personal AI assistant that is always on, reachable from your Mac, phone, and Telegram, and never exposed to the internet.
- Replacing an OpenClaw setup that sat behind a public domain, extra login, or custom proxy.
- Running OpenClaw agents and automations on managed infrastructure instead of a home server.

## Dependencies for OpenClaw Private Gateway Hosting

- A Railway account on a paid plan (two services with volumes).
- A Tailscale tailnet with MagicDNS and HTTPS certificates enabled, and an auth key.
- An API key for your model provider (for example Anthropic or OpenAI), added after deploy.

### Implementation Details

Both services build from [github.com/stevekinney/openclaw-railway-template](https://github.com/stevekinney/openclaw-railway-template). The openclaw image is the official `ghcr.io/openclaw/openclaw` release pinned by digest, plus a small entrypoint that prepares the volume, writes a baseline config on first boot only, and drops root privileges. The tailscale service builds from the repo's `tailscale/` directory with the official `tailscale/tailscale` image. Upgrades are a one-line version change in the repository. The repository's docs cover the architecture, security model, upgrades, and troubleshooting.

## Why Deploy OpenClaw Private Gateway on Railway?

Railway is a singular platform to deploy your infrastructure stack. Railway will host your infrastructure so you don't have to deal with configuration, while allowing you to vertically and horizontally scale it.

By deploying OpenClaw Private Gateway on Railway, you are one step closer to supporting a complete full-stack application with minimal burden. Host your servers, databases, AI agents, and more on Railway.


## Similar templates

- [Chat Chat](https://railway.com/deploy/-WWW5r) — Chat Chat, your own unified chat and search to AI platform.
- [stella](https://railway.com/deploy/stella) — Self-host stella with web, API, Postgres, Redis, and object storage.
- [Hermes Agent | OpenClaw Alternative with Dashboard](https://railway.com/deploy/hermes-agent-or-openclaw-alternative-wit) — Self-Hosted Hermes AI Agent for Telegram, Discord & Slack

Open this page in a browser: https://railway.com/deploy/openclaw-private-gateway
