Why Azure, Not Your Laptop
The Security Reality
Running OpenClaw on your personal computer is risky. This is not speculation. Microsoft's Security Team warned in February 2026 that OpenClaw should be treated as untrusted code execution with persistent credentials, and should only run in a fully isolated environment such as a dedicated VM.
The core risks when running locally:
- Full system access: OpenClaw can run shell commands, read/write files, and execute scripts on your machine.
- Credential exposure: Config, memory, and chat logs store API keys and passwords in plain text. Infostealers (RedLine, Lumma, Vidar) have already added OpenClaw file paths to their target lists.
- Critical CVEs: CVE-2026-25253 allowed any website you visit to silently hijack your local OpenClaw gateway via WebSocket. CVE-2026-24763 and CVE-2026-25157 were command injection flaws.
- Malicious skills: 341+ malicious skills found on ClawHub. The #1 ranked skill was confirmed malware by Cisco.
- Prompt injection: External content (emails, web pages, documents) can trick the agent into performing unintended actions.
Why Azure Works
A dedicated Azure VM solves the main problems:
- Your personal files, browser sessions, and credentials are not on the same machine.
- If the VM gets compromised, your laptop is unaffected. You delete the VM and start over.
- Azure NSG (Network Security Groups) let you lock down network access.
- You can deallocate the VM when not using it and stop paying for compute.
Key Security Rules
Regardless of where you run OpenClaw:
- Keep OpenClaw updated. Patches ship multiple times per week.
- Never expose the gateway to the public internet without authentication.
- Never install skills from ClawHub without reading the source code first.
- Run
openclaw security audit --deepafter setup and periodically. - Use a strong gateway token/password (not "a" or "password").
- Do not sign the VM into your personal Apple/Google/password-manager accounts.
Create Your Azure VM
There are multiple ways to deploy OpenClaw on Azure. Below is the cheapest path that still gives you proper security. We skip Azure Bastion (which costs ~$140/month) and use IP-restricted SSH instead.
Option A: One-Click Deployment (Easiest)
The community repo aerolalit/openclaw-azure automates everything. It creates a VM, locks SSH to your IP, sets up OpenClaw, and optionally enables daily backups.
What you need before starting:
- An Azure account (free trial works for testing)
- Azure CLI installed on your laptop (
azcommand) - An API key for your LLM provider (Anthropic, OpenAI, or Azure OpenAI)
- A Telegram bot token (from @BotFather) if you want Telegram access
Steps:
Install Azure CLI if you haven't:
# macOS:
brew install azure-cli
# Windows: download from https://aka.ms/installazurecliwindows
# Linux:
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
Log in to Azure:
az login
Clone the deployment repo:
git clone https://github.com/aerolalit/openclaw-azure.git
cd openclaw-azure
Configure your parameters:
cp deploy/parameters.json.example deploy/parameters.json
# Edit deploy/parameters.json with your values:
# - Your API key
# - Your Telegram bot token (optional)
# - Pick a region: westeurope or northeurope for NL
# - App name: 3-12 characters, letters/numbers only
Deploy:
./deploy/deploy.sh
This takes 5-10 minutes. Your IP is automatically restricted in the NSG.
Wait for cloud-init to finish, then test:
az vm run-command invoke \
--resource-group <your-rg> \
--name <your-vm> \
--command-id RunShellScript \
--scripts 'journalctl -u openclaw -n 50 --no-pager'
Tip: Region Choice. Use
westeurope(Amsterdam) ornortheurope(Dublin) for lowest latency from Europe.westeuropeis usually cheaper and has the widest VM selection.
Option B: Manual Azure CLI Setup
If you prefer more control, here are the core steps:
Create a resource group:
az group create --name rg-openclaw --location westeurope
Create an NSG and lock SSH to your IP:
az network nsg create --resource-group rg-openclaw \
--name nsg-openclaw
az network nsg rule create --resource-group rg-openclaw \
--nsg-name nsg-openclaw --name AllowSSH \
--priority 100 --direction Inbound \
--source-address-prefixes <YOUR_PUBLIC_IP> \
--destination-port-ranges 22 --access Allow \
--protocol Tcp
Create the VM:
az vm create \
--resource-group rg-openclaw \
--name vm-openclaw \
--image Ubuntu2404 \
--size Standard_B2s \
--admin-username openclaw \
--generate-ssh-keys \
--nsg nsg-openclaw \
--public-ip-sku Standard
About VM size: Standard_B2s gives you 2 CPU cores and 4 GB RAM. This is enough for a single OpenClaw agent. If you plan to run heavier workloads later, Standard_D2as_v4 (2 CPU, 8 GB RAM) gives more headroom.
Install OpenClaw
SSH into your new VM:
ssh openclaw@<VM_PUBLIC_IP>
Install Node.js 22+:
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
Install OpenClaw:
npm install -g openclaw@latest
openclaw onboard --install-daemon
The onboard wizard will ask you a few questions. For now, just pick defaults. we will configure the LLM provider in the next step.
Verify it is running:
openclaw gateway status
You should see the gateway is active. If not, check the logs:
cat /tmp/openclaw/openclaw-*.log | tail -50
Connect an LLM Provider
OpenClaw is installed, but without an LLM it has no brain. You need to connect it to a language model. There are three options depending on what you prefer.
Option 1: Anthropic (Claude). simplest
If you have an Anthropic API key, this is the fastest way to get going.
openclaw config set models.providers.anthropic.apiKey "sk-ant-YOUR-KEY-HERE"
openclaw gateway restart
OpenClaw will automatically detect available Claude models. To set your default model:
openclaw config set agents.defaults.model.primary "anthropic/claude-sonnet-4-6"
Option 2: OpenAI (GPT). also simple
If you prefer OpenAI:
openclaw config set models.providers.openai.apiKey "sk-YOUR-KEY-HERE"
openclaw gateway restart
Set your default model:
openclaw config set agents.defaults.model.primary "openai/gpt-4o"
Option 3: Azure OpenAI via Foundry. advanced
If you want everything inside your Azure subscription (one bill, data stays in your tenant), you can deploy models through Azure AI Foundry instead of using Anthropic or OpenAI directly.
Set up models in Foundry:
- In the Azure portal, open your AI Foundry hub (or create one).
- Go to the Model Catalog, deploy
gpt-4o(or whichever model you want). - Go to Endpoints. Save these two values:
- Endpoint URL (format:
https://<YOUR_RESOURCE>.openai.azure.com - API Key (found under Keys in the Azure Portal)
- Endpoint URL (format:
Configure OpenClaw to use Foundry:
Edit ~/.openclaw/openclaw.json and add the following under models.providers:
{
"azure-openai-responses": {
"baseUrl": "https://<YOUR_RESOURCE>.openai.azure.com/openai/v1",
"apiKey": "<YOUR_AZURE_API_KEY>",
"api": "openai-responses",
"authHeader": false,
"headers": {
"api-key": "<YOUR_AZURE_API_KEY>"
},
"models": [
{
"id": "gpt-4o",
"name": "GPT-4o (Azure)",
"reasoning": false,
"input": ["text", "image"],
"cost": {
"input": 2.5,
"output": 10.0,
"cacheRead": 1.25,
"cacheWrite": 0
},
"contextWindow": 128000,
"maxTokens": 16384,
"compat": { "supportsStore": false }
}
]
}
}
Then set it as the default:
openclaw config set agents.defaults.model.primary "azure-openai-responses/gpt-4o"
openclaw gateway restart
Important: API Key Goes in Two Places. Azure OpenAI uses the
api-keyHTTP header, not the standard Bearer token. Your key must appear in both theapiKeyfield and theheaders.api-keyfield. TheauthHeader: falsesetting disables the default Bearer header so it does not conflict.
Which option should I pick?
- Anthropic or OpenAI - if you just want it working fast. Sign up, get an API key, paste it in. Done.
- Azure OpenAI - if you want everything in one Azure bill, or if your company provides Azure OpenAI access. More setup, but gives you Azure cost management and spending alerts.
You can always switch later. OpenClaw supports multiple providers at the same time.
Set Up Telegram
With the LLM connected, your agent can think. Now give it a way to talk to you.
The dashboard is available immediately - access it via SSH tunnel:
# From your laptop, create an SSH tunnel:
ssh -L 18789:localhost:18789 openclaw@<VM_PUBLIC_IP>
# Then open in your browser:
# http://localhost:18789
But Telegram is more practical for daily use. Set it up:
- Open Telegram and message @BotFather
- Send
/newbot, follow the prompts, copy the bot token - On the VM:
openclaw config set channels.telegram.botToken "YOUR_BOT_TOKEN"
openclaw config set channels.telegram.enabled true
openclaw gateway restart
- Open Telegram and message your new bot. Approve the pairing when prompted.
Send Your First Message
Open your Telegram bot and type something simple:
Hi, what can you help me with?
If everything is connected, your agent will respond. Congratulations, you have a working AI agent running on Azure.
If it does not respond:
- Check gateway status:
openclaw gateway status - Check the logs:
cat /tmp/openclaw/openclaw-*.log | tail -50 - Verify your API key is set:
openclaw config get models - Make sure the Telegram bot token is correct:
openclaw config get channels.telegram
Saving Money
Deallocate When Not Using
When you are not using OpenClaw, deallocate the VM to stop paying for compute. You only pay for disk storage (~$1-4/month).
# Stop and deallocate (stops billing for compute):
az vm deallocate --resource-group rg-openclaw --name vm-openclaw
# Start it back up:
az vm start --resource-group rg-openclaw --name vm-openclaw
# The public IP may change after restart. Check with:
az vm show -d --resource-group rg-openclaw --name vm-openclaw \
--query publicIps -o tsv
Auto-Shutdown
Set up automatic deallocate so you do not forget:
Go to the Azure portal > your VM > Auto-shutdown > Enable. Set a time like 23:00 your local timezone. The VM will automatically stop every night.
Cost Breakdown
Azure Infrastructure
Estimated monthly costs for a B2s VM in West Europe:
| Component | Monthly (est.) | Notes |
|---|---|---|
| VM: Standard_B2s (2 vCPU, 4GB) | ~โฌ25-30 | ~โฌ0.04/hr, less if deallocated nights/weekends |
| OS Disk (30GB Standard SSD) | ~โฌ3-5 | Charged even when deallocated |
| Public IP (Standard SKU) | ~โฌ3-4 | Small charge while allocated |
| Outbound data transfer | ~โฌ1-3 | First 100GB/month is free |
| Total | ~โฌ32-42 | Without Azure Bastion (saves ~$140/month) |
LLM API Costs
This depends on your provider and usage. Rough estimates:
| Usage Level | Monthly (est.) | What that looks like |
|---|---|---|
| Light | ~$5-15 | A few questions per day |
| Medium | ~$15-40 | Daily active use, longer conversations |
| Heavy | ~$40-100+ | Automated tasks running throughout the day |
Tip: Monitor your token usage from day one. OpenClaw can burn through tokens fast, especially if you set up automated workflows later. Most LLM providers have usage dashboards and spending alerts.
Total Estimated Monthly Cost
| Scenario | Monthly Total |
|---|---|
| Budget (light use, deallocate often) | ~โฌ35-55 |
| Normal (daily use, VM mostly on) | ~โฌ50-80 |
| Heavy (always on, lots of agent work) | ~โฌ80-140+ |
Essential Commands
openclaw gateway status # Check if running
openclaw gateway restart # Restart after config changes
openclaw agents list --bindings # See all agents and routing
openclaw security audit --deep # Security check
openclaw dashboard # Open web UI
# Azure VM management:
az vm deallocate --resource-group rg-openclaw --name vm-openclaw
az vm start --resource-group rg-openclaw --name vm-openclaw
What's Next
You now have a working OpenClaw agent on Azure with a connected LLM and Telegram access. Here are some ideas for what to build next:
- Morning Briefing - set up a daily automated briefing delivered to Telegram with weather, news, and tasks. See our Morning Briefing guide.
- Secret Management - your API keys are currently in a config file. Learn how to store them properly. See our Secret Management guide.
- Customize your agent - edit
SOUL.mdandAGENTS.mdin your agent's workspace folder to give it a personality, rules, and focus areas.
Useful Links
- Official docs: docs.openclaw.ai
- Azure deployment guide: docs.openclaw.ai/install/azure
- Security docs: docs.openclaw.ai/gateway/security
- One-click Azure repo: github.com/aerolalit/openclaw-azure
Final tip. Start simple. Get your agent responding on Telegram before adding complexity. Once it works, explore the other guides on this site to add more capabilities.
What's Next?
Now that OpenClaw is running on your Azure VM, you're ready to build your first automation. Start with the Morning Briefing guide โ it walks you through setting up a personalized daily briefing delivered to Telegram at 8 AM.
Before you connect any paid APIs, make sure to set up proper secret management so your API keys stay safe.