Deploy QwenPaw Private Assistant
QwenPaw personal assistant: login on, shell tool off, one volume
QwenPaw
Just deployed
Deploy and Host QwenPaw on Railway
QwenPaw is an open source personal AI assistant from the AgentScope team. It gives you a web console and REST API for chatting with your own agents, with long term memory, skills, scheduled tasks, a built in browser tool, and connectors that let the same assistant answer you in Telegram, Discord, Slack, DingTalk, Feishu, QQ, WeChat and more. It works with Qwen models through DashScope and with OpenAI, Anthropic, Gemini, OpenRouter, DeepSeek or any OpenAI compatible endpoint.
About Hosting QwenPaw
QwenPaw runs as a single container. This template uses the official agentscope/qwenpaw:v2.2.1 image, the latest stable release, with one Railway volume at /data. Upstream Docker Compose uses three volumes (workspace, secrets, backups); the template points QWENPAW_WORKING_DIR, QWENPAW_SECRET_DIR and QWENPAW_BACKUP_DIR into that one volume, so your chats, your login, your encrypted model API keys and the key that decrypts them all survive redeploys. PORT and QWENPAW_PORT are pinned to 8088 so the healthcheck on /api/version reaches the app, and the start command sends the app's logs to the Railway log view.
The instance is private from the first boot. Login is switched on and your account is created automatically from a generated password, so nobody who finds the URL can register it first, and every API route needs a token. The agent's shell command tool is blocked by default, because a container has no sandbox and a shell command would run as root with access to your data and keys. You can allow it later by clearing one variable.
Common Use Cases
- Private AI assistant in your browser: chat with your own agents from any device through the web console
- One assistant across chat apps: connect Telegram, Discord, Slack, DingTalk, Feishu, QQ or WeChat to the same memory and skills
- Scheduled and proactive tasks: heartbeats and cron jobs that summarise, remind and report on a schedule
- Web research with a real browser: the agent drives Chromium inside the container to read and act on pages
- Multi agent setups: several agents with their own personas, models and tools in one instance
- REST API for your own apps: stream agent replies into scripts or other services with a bearer token
Dependencies for QwenPaw Hosting
- Railway volume at
/data(included) - An LLM provider API key: not needed to boot. Add it in the console under Settings, Models (DashScope, OpenAI, Anthropic, Gemini, OpenRouter, DeepSeek, custom OpenAI compatible endpoints and more)
- Chat app bot credentials: optional, only for the channels you connect
- Hobby plan or higher recommended: the container runs the app plus a virtual desktop and Chromium for the browser tool
Deployment Dependencies
- QwenPaw documentation
- Docker quickstart
- Security guide (login, tool guard, sandbox)
- Channels guide
- QwenPaw GitHub repository
Implementation Details
Key variables set by the template:
PORT=8088
QWENPAW_PORT=8088
QWENPAW_WORKING_DIR=/data/working
QWENPAW_SECRET_DIR=/data/working.secret
QWENPAW_BACKUP_DIR=/data/working.backups
QWENPAW_AUTH_ENABLED=true
QWENPAW_AUTH_USERNAME=admin
QWENPAW_AUTH_PASSWORD=${{secret(32)}}
QWENPAW_TOOL_GUARD_ENABLED=true
QWENPAW_TOOL_GUARD_DENIED_TOOLS=execute_shell_command
First steps after deploy
- Wait for the healthcheck on
/api/versionto pass. The first boot pulls about 1 GB and initialises the workspace. - Open your Railway domain and sign in with
QWENPAW_AUTH_USERNAMEandQWENPAW_AUTH_PASSWORDfrom the service variables. - Go to Settings, Models, add your provider API key and choose the active model.
- The default agent's persona files are in Chinese; switch the agent language to English in its settings if you prefer.
- Start chatting in the console, or connect a chat app under Control, Channels. Turn on the channel's access control allowlist so only you can talk to the bot.
The password variable is only used on the first boot to create the account. To change the password later, use the console profile settings or run qwenpaw auth reset-password in a Railway shell. Channels that need inbound UDP (SIP) or macOS (iMessage) do not work on Railway.
Why Deploy QwenPaw on Railway?
Railway is a singular platform to deploy your infrastructure stack. Railway will host your infrastructure so you don't have to deal with configuration, while allowing you to vertically and horizontally scale it.
By deploying QwenPaw on Railway, you get an always on personal assistant with a pinned release, persistent storage for memory and encrypted keys, login protection from the first boot, managed SSL, and a public URL your chat apps and devices can reach.
Template Content
QwenPaw
agentscope/qwenpaw:v2.2.1