The best self-hosted AI agents in 2026 (assistants, not frameworks)
Most "best self-hosted AI agent" lists are written by hosting vendors, rank their own product first, or mix assistants with developer frameworks. This one covers assistants only, names each one's weak spot, and lists our own product as the only commercial, closed-source entry.
The short answer: there is no single best self-hosted AI agent, only a best one for your situation. OpenClaw has the biggest ecosystem and the most chat channels. Hermes Agent is the pick if you want an agent that curates its own memory. NanoClaw suits Claude users who want each agent isolated in a container, and PicoClaw suits tiny hardware. Avelina AI, which is ours, is the pick if you want a finished, Telegram-native assistant with a personality, installed in about 30 minutes, and you accept closed code and Claude as the only model.
A self-hosted AI agent is an assistant whose process, memory and files live on hardware you control; usually only the call to the language model leaves it. Background: self-hosted AI versus cloud AI.
How we built this list. Facts come from each project's README, official docs and the GitHub API, checked on October 10, 2026. We did not run all of them ourselves. Where a README is silent we write "not documented", not "no". Stars are GitHub snapshots. The order reflects openness and ecosystem size, not a score; the only closed product comes last.
The ranking
1. OpenClaw
What it is: an open-source assistant that runs a gateway process on your computer or server and connects to your chat apps. Hosting: Mac, Windows or Linux; Node 24.16+ or 26.1+. Memory: plain Markdown files (MEMORY.md, daily logs, USER.md) with hybrid vector and keyword search. Persona: SOUL.md and IDENTITY.md. Automation: built-in cron and sub-agents. Channels: 29 on its site, including Telegram. Licence and price: MIT, free; you pay your model provider. About 391,500 stars (GitHub, October 2026). Best for: the largest ecosystem, if you will curate it. Drawback: the biggest security surface on this list (see the security section below). Versus ours: Avelina vs OpenClaw.
2. Hermes Agent (Nous Research)
What it is: a self-improving agent with a learning loop and one gateway for several chat apps. Hosting: a one-line installer for Linux, macOS and WSL2, with seven terminal backends including Docker and SSH; the README claims a $5 VPS is enough. Memory: agent-curated memory, full-text session search with summaries, and user modelling. Persona: a /personality command. Automation: natural-language cron delivering to any platform, plus isolated parallel sub-agents. Channels: Telegram, Discord, Slack, WhatsApp and Signal; Telegram needs an allow-list and denies everyone if it is unset. Licence and price: MIT, free; about 252,300 stars (GitHub, October 2026). Best for: self-improving memory; a command imports from OpenClaw. Drawback: still a 0.x release (v0.21.6), so expect change.
3. NanoClaw
What it is: a small OpenClaw alternative where each agent runs in its own Docker container on the Claude Agent SDK. Hosting: macOS, Linux or WSL2; Docker is required. Memory: per-agent CLAUDE.md files. Persona: the same file. Automation: scheduled tasks, and you can spawn teammates from chat, each with its own container and memory. Channels: WhatsApp, Telegram, Discord, Slack and more, added as skills. Licence and price: MIT, free; about 30,900 stars (GitHub, October 2026). Best for: Claude users who want isolation. Drawback: Claude is the default brain, and other models (Codex, OpenCode, Ollama) arrive as add-on skills.
4. ZeroClaw
What it is: an agent runtime shipped as a single Rust binary. Hosting: prebuilt binary or Docker; default autonomy is "supervised". Memory: SQLite plus embeddings. Persona: not documented in the README. Automation: cron management and an SOP engine triggered by cron, MQTT or webhooks; sub-agents not documented. Channels: 30+, including Telegram, Discord, Matrix and email. Licence and price: free and permissive, dual-licensed MIT OR Apache-2.0 (both LICENSE files are in the repo; GitHub's API shows only Apache-2.0). About 32,900 stars (GitHub, October 2026). Best for: a small binary with many channels. Drawback: persona and delegation are thinly documented.
5. Nanobot (HKUDS)
What it is: a lightweight Python project that calls itself an agent framework but ships a working assistant with a WebUI and chat channels, hence its place here. Hosting: pip install, Docker, Compose, systemd or LaunchAgent. Memory: session history plus long-term memory through a process called Dream. Persona: not found in the README sections we read. Automation: cron and multi-agent delegation. Channels: WebUI, Telegram, Discord, Slack, email and several Asian messengers. Licence and price: MIT, free; about 48,900 stars (GitHub, October 2026). Best for: Python users who want to modify the code. Drawback: 0.x release (v0.3.5) and no documented persona layer.
6. PicoClaw (Sipeed)
What it is: a Go assistant inspired by Nanobot, built for very small hardware. Hosting: prebuilt binaries, make install or Docker Compose. The README claims under 10 MB of RAM and admits recent builds use 10 to 20 MB. Memory: a JSONL store. Persona: not found. Automation: cron and sub-turns. Channels: Telegram, Matrix, IRC, Discord, WeChat and others. Licence and price: MIT, free; about 30,000 stars (GitHub, October 2026). Best for: a spare single-board computer. Drawback: its latest release (v0.3.1) is dated July 3, 2026, older than most of the list.
7. Letta Code
What it is: the active code of Letta (formerly MemGPT), a platform for stateful agents with learning memory. Hosting: npm install and a local server, or Letta Cloud. Memory: memory blocks, a git-tracked store you can sync to your own repository, and "dreaming". Persona: a personality flag plus memory blocks. Automation: crons, heartbeats and sub-agents. Channels: Slack, Telegram, Discord, custom channels. Licence and price: Apache-2.0, open source is free; cloud pricing not checked. About 3,560 stars for letta-code (GitHub, October 2026). Best for: memory-design enthusiasts. Drawback: the older letta repository keeps the retired V1 API server on an archive branch; current development is in letta-code, so tutorials found online may point at the wrong project.
8. Avelina AI (ours)
What it is: a commercial personal agent that lives in Telegram on your own VPS or Mac. Hosting: a $5 to 15 a month VPS with 2 to 4 GB of RAM, because the server holds state, not model inference; a guided install takes about 30 minutes. Memory: four typed layers (facts, events, corrections, inferences), each with its own lifetime, in local databases. Persona: a SOUL.md personality file with a biography and tone. Automation: cron and sub-agents. Channels: Telegram (text and voice) plus an optional macOS app. Licence and price: not open source; €280 one-time (self-install) or €480 with a guided session, plus your own VPS and your own Claude subscription or API usage. Releases are signed. Best for: an assistant that arrives working. Drawbacks: closed code, so you cannot audit it yourself; Claude is the only model; no public community to lean on. More on the AI agent page.
Summary table
| Agent | Runs where | Licence | Memory | Persona | Cron / sub-agents | Telegram | Price |
|---|---|---|---|---|---|---|---|
| OpenClaw | Your machine or server | MIT | Markdown files, hybrid search | SOUL.md, IDENTITY.md | Both | Yes | Free, plus model API |
| Hermes Agent | Your machine or server | MIT | Agent-curated, searchable | /personality command | Both | Yes | Free, plus model API |
| NanoClaw | Your machine, in Docker | MIT | Per-agent CLAUDE.md | Per-agent CLAUDE.md | Both | Yes (as a skill) | Free, plus model API |
| ZeroClaw | Your machine, one binary | MIT OR Apache-2.0 | SQLite plus embeddings | Not documented | Cron yes; sub-agents not documented | Yes | Free, plus model API |
| Nanobot | Your machine or server | MIT | History plus Dream | Not documented | Both | Yes | Free, plus model API |
| PicoClaw | Your machine, small hardware | MIT | JSONL store | Not documented | Both | Yes | Free, plus model API |
| Letta Code | Your machine, or Letta Cloud | Apache-2.0 | Memory blocks, git-tracked | Personality flag | Both | Yes | Open source free; cloud not checked |
| Avelina AI | Your VPS or Mac | Commercial, closed | Four typed layers | SOUL.md personality | Both | Yes, native | €280 or €480 one-time, plus VPS and Claude |
Assistants vs frameworks vs UIs
Some famous names are missing on purpose.
Frameworks such as LangGraph and CrewAI are libraries for developers who build agents; there is no assistant until you write one. Workflow builders such as Dify (modified Apache 2.0 with extra conditions) and n8n (fair-code rather than a standard open-source licence; confirm on n8n.io) are visual pipelines. Chat UIs with agent features are the third group: LibreChat, AnythingLLM and Open WebUI are strong self-hosted interfaces with agents and MCP, and in some cases scheduled tasks (AnythingLLM, Open WebUI), but they are built around a browser window. We did not find Telegram in the READMEs we read. Open WebUI also uses a custom licence with a branding requirement.
One flag: Khoj, an "AI second brain", shows low activity. Its latest tagged release is a March 2026 beta (last push August 2026) and its README promotes a newer project, Pipali.
Security before you self-host an agent
An agent that reads your mail and runs commands is a high-value target. All figures below are third-party reports.
Malicious skills. OpenClaw's community registry, ClawHub, had a supply-chain problem. Researchers flagged 341 malicious skills on ClawHub, 335 of them from one coordinated campaign. Later tallies went higher (Bitdefender about 900, per Conscia; one count over 820), so the numbers vary by audit and date. Palo Alto Networks Unit 42 reported evasive malicious skills persisting from February to May 2026.
A critical flaw. CVE-2026-25253 (CVSS 8.8, affects versions before 2026.1.29) is a one-click RCE per the vendor advisory GHSA-g8p2-7wf7-98mq; NVD record: https://nvd.nist.gov/vuln/detail/CVE-2026-25253. Verify your patched version.
Over-privilege. DigitalOcean notes that a skill inherits the agent's system permissions, so one bad skill gets everything the agent has.
The general lesson applies to every product here, ours included. Use allow-lists so only your account can talk to the agent. Prefer isolation such as containers. Grant least privilege and add skills one at a time from sources you can name. Favour signed releases. Closed source is a trade-off: you cannot read the code and rely on the vendor and signing instead. None of this makes self-hosting a bad idea; it means you are the operator.
Which one should you pick?
Biggest ecosystem, and you will vet skills: OpenClaw (or see OpenClaw alternatives). Self-curating memory: Hermes. Claude plus containers: NanoClaw. Tiny hardware: PicoClaw. A small Python codebase: Nanobot. Finished, in Telegram, with eyes open about closed code: Avelina AI. For the server side, read how to deploy an assistant on a VPS and how to run an agent 24/7.
FAQ
What is a self-hosted AI agent?
An assistant whose process, memory and files run on hardware you control, such as a home machine or a rented VPS. It remembers you, uses tools, and runs continuously.
Do I need my own API key?
Usually yes. Most agents here are free software, and you pay a model provider through an API key, a subscription, or a local model such as Ollama. Avelina AI uses your own Claude subscription or API usage.
How much RAM or what VPS do I need?
It depends on the agent. PicoClaw claims under 10 MB, with recent builds at 10 to 20 MB (its README). Hermes claims a $5 VPS works. Avelina AI recommends a $5 to 15 a month VPS with 2 to 4 GB of RAM.
Which self-hosted agent is the safest?
None is safe by default. Container isolation (NanoClaw), a deny-by-default allow-list (Hermes) and a supervised default (ZeroClaw) reduce risk, and open source lets you audit the code. Whichever you pick, restrict who can message it and vet every skill.
Which has the best memory?
It depends on what you mean. OpenClaw's plain Markdown is the easiest to inspect, Hermes and Letta Code let the agent curate memory, and Avelina AI separates facts, events, corrections and inferences with different lifetimes. See the four memory layers.