# Self-host an open-source OpenClaw alternative with Kortix

description: Run an open-source OpenClaw alternative on your own box: install Kortix, scaffold a project, and self-host the whole AI Operating System in three commands.

Self-hosting an OpenClaw alternative means running the agent stack on hardware you control, and Kortix is the open-source AI Operating System you deploy there. Kortix keeps your agents, their skills, your company memory and every connector in one git repo you own, and it runs each session on its own isolated cloud computer. You self-host it as one Docker Compose deployment on a laptop, a VPS, your VPC or an on-prem network, or use Kortix Cloud instead.

OpenClaw is an open-source AI assistant that runs on your own computer and reaches you through the chat apps you already use, including Discord, iMessage, Slack, Teams, Telegram and WhatsApp, plus native apps for macOS, iOS, Android, Windows and Linux ([OpenClaw on GitHub](https://github.com/openclaw/openclaw)). It is MIT-licensed, stewarded by the independent OpenClaw Foundation, and has no paid tier or hosted service ([openclaw.ai](https://openclaw.ai)). That shape fits one person's assistant well. A company that self-hosts asks for more: configuration a team can diff, policy on every tool call, and a gate before an agent's change takes effect.

## Where the two self-hosting models differ

| Dimension | Kortix (self-hosted) | OpenClaw (self-hosted) |
|---|---|---|
| Open source | Yes | Yes |
| What you run | The full AI Operating System and control plane | A gateway that bridges chat apps to agents |
| Configuration | Files in a git repo you own | `~/.openclaw/openclaw.json` on the machine |
| Sessions | An isolated Linux sandbox per session | Tools run on the host without extra sandboxing |
| How work lands | A change request a person reviews | Directly in the tools you connect |
| Models | Any provider, with your own keys | Plugins: Claude, Codex or local models |
| Licence | Elastic License 2.0 | MIT |

If you are still choosing between the two, the [Kortix vs OpenClaw comparison](/kortix-vs-openclaw.html) and the list of [open-source OpenClaw alternatives](/openclaw-alternatives.html) cover the decision from other angles, and the [home page](/) has the short version.

## What you own when you self-host Kortix

Kortix is the leading open-source alternative to Claude Cowork and ChatGPT Work, and self-hosting moves that system inside your own network. The company's whole configuration is one git repo: agents, skills, memory, connector config and triggers are text files in it, and `kortix.yaml` declares the machine image, the connectors and the triggers ([Kortix docs](https://kortix.com/docs)). Because every part is a file, you can grep the whole company, diff any change, and roll any part of it back.

Self-hosting changes where that repo and its runtime live. The contents stay the same, and the self-hosted distribution is the whole control plane (accounts, projects, repos, secrets, connectors, policies and audit) running inside your network on storage you back up yourself ([Kortix self-hosting](https://kortix.com/self-hosted)). It runs the same images as the managed cloud, from the same release train. Kortix is open source (Elastic License 2.0): self-host, read and modify the code.

## Prerequisites

A self-hosted instance needs four things before the first command:

- A Linux box with 2 vCPU and 4 GB RAM as the floor, and 4 vCPU and 16 GB or more for real use. A VPS, a cloud VM or a machine on your own network all work.
- A domain you control, with an A or AAAA record for the domain and for `api.<domain>` pointing at the box, and ports 80 and 443 reachable so the bundled Caddy proxy can issue a TLS certificate.
- A sandbox provider key. Agent sessions run on separate managed compute, not on the self-host box; Daytona is the default, and E2B and Platinum are also supported.
- An admin email, which becomes platform admin on first sign-up.

## Step 1: Install the Kortix CLI

On macOS or Linux, install the CLI with the one-line installer:

```sh
curl -fsSL https://kortix.com/install | bash
```

The installer downloads a prebuilt binary for macOS and Linux, and Windows is not supported for the CLI ([Kortix CLI reference](https://kortix.com/docs/cli)). Run `kortix version` to confirm the binary is on your path.

## Step 2: Bring up your own instance

With Docker present, initialize and start the stack on the box:

```sh
kortix self-host init --domain app.example.com
kortix self-host start
```

`kortix self-host init` renders `docker-compose.yml` and `.env` (plus a `Caddyfile` and `updater.sh` when you set a domain) into `~/.config/kortix/self-host/<instance>/`, and `kortix self-host start` runs `docker compose up` ([Kortix self-hosting guide](https://kortix.com/docs/host), [Kortix self-hosting architecture](https://kortix.com/docs/host/architecture)).

There is also a one-shot bootstrap script for a bare Linux box that installs Docker if it is missing, installs the CLI and drives the same init and start flow, and re-running it is safe. On another operating system, install the CLI directly and use the manual path above.

The `init` step is a short guided flow: it confirms the domain and DNS check, takes the admin email, asks whether you hold an Enterprise licence, takes the sandbox provider and its key, offers optional Pipedream credentials for the 3,000+ app catalog, and sets the update policy. While the stack starts, `kortix self-host status`, `kortix self-host logs` and `kortix self-host doctor` report what is happening.

If you have no public domain yet, start in evaluation mode with `kortix self-host init --tunnel cloudflare`, then `kortix self-host start`. The tunnel URL changes on every restart, and a sandbox with nothing to call back to cannot run sessions, so tunnel mode is for evaluation rather than production.

## Step 3: Finish setup in the dashboard

Open your domain in a browser and sign up with the admin email from the init flow. Two settings make the instance usable:

- Settings → Git: connect a GitHub App or a personal access token so the platform can create project repos.
- Settings → Model: connect your own model key, for example Anthropic, OpenAI or OpenRouter.

Both are set in the dashboard after the stack is up.

## Step 4: Scaffold a company project as a repo

A Kortix company is a project directory that is also a git repo. Scaffold one with:

```sh
kortix init my-app
cd my-app
```

`kortix init` creates a project directory with the general-purpose starter, and its `kortix.yaml` declares `kortix_version: 2` and runs the OpenCode harness. From there you edit the files that define the company: `agents/` for who does the work, `skills/` for how a job gets done, `memory/` for what the company has learned, and `kortix.yaml` for rules, triggers, connectors and the machine image.

## Step 5: Ship it and start a session

`kortix ship` lints your `kortix.yaml`, commits local changes, pushes your branch and prompts for any missing secret or connection. The first run also creates the cloud project and repo if you have not linked one. Then start work from the terminal:

```sh
kortix sessions new --prompt "Summarize this week's commits and open a change request" --wait
kortix cr ls
```

Every session runs in its own sandbox on its own branch. `kortix cr diff <cr>` shows the unified patch and `kortix cr merge <cr>` merges it into the default branch, so you read what an agent proposes before it lands ([Kortix CLI reference](https://kortix.com/docs/cli)).

## Models and keys on your own box

Kortix is model-agnostic, and you choose the model per agent, per session or per message. A self-hosted instance has no managed model lineup: you connect the providers you already pay for, and every model call routes through the LLM gateway running on your own box. Point Kortix at Anthropic, OpenAI, Google, Groq, xAI, DeepSeek, Mistral, Bedrock or OpenRouter, or sign in with the ChatGPT or Copilot subscription you already hold. Set a key with `kortix providers set anthropic sk-ant-...`, sign in to a subscription with `kortix providers login chatgpt`, and list what is connected with `kortix providers ls` ([Kortix self-hosting](https://kortix.com/self-hosted)). Keys are stored as encrypted project secrets and injected when a session boots.

## Governance on your own metal

Self-hosting puts the governance layer on your own infrastructure. The controls that matter for a company running agents:

- Every tool call can be set to allow, ask or block, down to the arguments of the call. An ask holds the call until a person approves it, then the agent resumes. Approval gates are off until you turn them on.
- Connector credentials are brokered server-side and never enter the machine, and secrets are encrypted at rest with a key per project.
- Work reaches the default branch only through a change request a person reads as a diff. Merge is default-deny for agents.
- Each session gets its own disposable Linux sandbox on its own branch. The agent can install, run and break anything, and only what it commits survives. Thousands run in parallel without crossover.

Those controls are declared per project in `kortix.yaml` and the dashboard ([Kortix on GitHub](https://github.com/kortix-ai/suna)). Access is per-resource for people and agents, with roles, groups and an audit trail; SAML 2.0 single sign-on and SCIM 2.0 directory sync unlock with an Enterprise licence on a self-hosted instance ([Kortix self-hosting](https://kortix.com/self-hosted)).

## Day-2 notes and troubleshooting

| Symptom or task | What to do |
|---|---|
| Sessions cannot start | Point a real domain at the box, or use tunnel mode |
| API containers hit the memory limit | `kortix self-host env set KORTIX_API_MEMORY_LIMIT=1024m` on a 16 GiB host |
| You need a backup | Copy `volumes/db/data`, `volumes/storage` and the instance `.env` |
| You want a fixed version | `kortix self-host update --tag 0.9.84` |
| You need a rotated secret | `kortix self-host env rotate <KEY>` |

The bootstrap script runs on Linux only, the updater checks once a day on a schedule you set, and instances track a `stable` or `latest` channel unless you pin a version. The [Kortix self-hosting guide](https://kortix.com/docs/host) and the [Kortix self-hosting architecture](https://kortix.com/docs/host/architecture) document the flags, the update channels and the backup layout.

Self-hosting an OpenClaw alternative gives a team the ownership OpenClaw promises, with the configuration, connectors and review gate a company needs. Install the CLI and bring the whole system up on your own box with open-source [Kortix](https://kortix.com).
