Deployment guide

How to Host Open WebUI on a VPS

Deploy on a VPS Cloud →

Tutorial

How to Host Open WebUI on a VPS

Artificial Intelligence8 min read5 steps

Open WebUI is an open source web interface that lets you interact with language models (LLMs) such as Llama, Mistral, or Ollama from a browser. Hosted on your own VPS, it gives you full access to your models, without relying on a third-party service and without exposing your data to external infrastructure.

Contents· Why host Open WebUI on a VPS rather than locally?1/10
  1. 01Why host Open WebUI on a VPS rather than locally?
  2. 02Local, VPS or SaaS: which solution for Open WebUI?
  3. 03What You Can Do With Open WebUI
  4. 04Prerequisites
  5. 05Deployment in 5 steps
  6. 06The shortcut: install from the Marketplace
  7. 07Pin the signing key from the very first start
  8. 08Configuring multi-user access
  9. 09Troubleshooting: common problems
  10. 10The Official Documentation

Why host Open WebUI on a VPS rather than locally?

Local hosting works for testing, but it has real limits in production: it consumes machine resources, offers no remote access, and provides no high availability. A VPS solves these problems: it runs 24/7, is accessible from any device, and gives you full control.

The difference from a cloud SaaS service is equally clear. A managed AI tool bills per usage, stores your conversations on third-party servers, and limits the models available. Self-hosted Open WebUI removes all three constraints: you pay for the VPS, not the requests, your data stays on your machine, and you choose the model that suits you.

Local, VPS or SaaS: which solution for Open WebUI?

Scroll the table

CriterionLocal machineDedicated VPSCloud SaaS
24/7 access from anywhereNoYesYes
Data on your infrastructureYesYesNo
Free choice of LLMFreeFreeLimited to the offer
Cost beyond fixed resourcesNoneNonePer-usage billing
Multi-user and rolesDifficultYes (built-in)Depends on plan
Installation and maintenanceManualManual or MarketplaceNone

What You Can Do With Open WebUI

  • Chat with local models via Ollama (Mistral, LLaMA 3, Gemma, etc.) or with the OpenAI API
  • Manage several models and switch between them in one click from a unified interface
  • Create and share custom assistants with tailored system instructions
  • Upload and analyse documents (PDF, text) directly in the chat thanks to built-in RAG support
  • Open access to your team with a system of user accounts and roles
  • Review the full history of your conversations, stored on your own server

Prerequisites

Open WebUI requires Docker to run. Ollama (if you want to run an LLM locally on the server) is RAM-hungry. Plan for at least 4 GB of RAM for a 7B model, and 8 GB for a 13B model. If you only use external APIs (OpenAI, Anthropic), 2 GB of RAM is enough for the interface.

On the storage side, Ollama models weigh between 4 and 40 GB depending on their size. Plan for a SSD volume with at least 20 GB free if you intend to download a 7B model such as Mistral or LLaMA 3.

Deployment in 5 steps

  1. Prepare your VPS

    Order a Cloud VPS with Ubuntu 22.04 LTS. Update the system:

    apt update && apt upgrade -y

    Enable the UFW firewall and allow the SSH (22), HTTP (80), and HTTPS (443) ports:

    ufw allow 22 && ufw allow 80 && ufw allow 443 && ufw enable
  2. Install Docker

    Install Docker Engine from the official Docker repository. Add your user to the docker group to avoid repeated sudo commands:

    curl -fsSL https://get.docker.com | sh
    usermod -aG docker $USER

    Verify the installation: docker run hello-world.

  3. Start Open WebUI

    Pull the official Docker image and launch the container, exposing port 3000. Mount a volume to persist data across restarts:

    docker run -d \
      --name open-webui \
      --restart always \
      -p 3000:8080 \
      -v open-webui:/app/backend/data \
      -e WEBUI_SECRET_KEY=$(openssl rand -hex 32) \
      ghcr.io/open-webui/open-webui:main

    Open WebUI is accessible at http://your-ip:3000. The WEBUI_SECRET_KEY variable is generated here at install time — note its value or place it in a .env file before restarting the container.

  4. Configure a reverse proxy (Nginx)

    Install Nginx and set up a virtual host that proxies requests to port 3000:

    apt install -y nginx certbot python3-certbot-nginx

    Create /etc/nginx/sites-available/open-webui with:

    server {
        server_name your-domain.com;
        location / {
            proxy_pass http://127.0.0.1:3000;
            proxy_http_version 1.1;
            proxy_set_header Upgrade $http_upgrade;
            proxy_set_header Connection "upgrade";
        }
    }

    Activate the vhost and get a Let's Encrypt SSL certificate: certbot --nginx -d your-domain.com. Your interface will be accessible over HTTPS on your domain.

  5. Connect your models

    In the Open WebUI interface, configure your API connections: local Ollama, OpenAI, Anthropic, or any other compatible provider. To start Ollama on the same VPS:

    docker run -d \
      --name ollama \
      --restart always \
      -v ollama:/root/.ollama \
      -p 11434:11434 \
      ollama/ollama

    Then download the model you want: docker exec ollama ollama pull mistral. In the Open WebUI settings, the Ollama URL is http://host.docker.internal:11434 if both containers are on the same host. Create user accounts as needed.

The shortcut: install from the Marketplace

If your VPS is a ServOrbit Cloud VPS, you do not have to walk through the steps above. From your client area, open the Marketplace in the server management panel, look up Open WebUI and confirm the install: the container and its dependencies are deployed for you. Two steps remain that nobody can take on your behalf — creating the administrator account on first connection (the first account created takes that role, so open it yourself without waiting) and declaring your model source in the admin settings. Plan for at least 4 GB of RAM and 2 vCPU if you run Ollama on the same machine: the interface is light, the models are what weigh. The manual route keeps its value as soon as you want control over the Docker composition, a pinned version, or Open WebUI wired into existing infrastructure.

Pin the signing key from the very first start

Open WebUI signs every session token with WEBUI_SECRET_KEY. If you do not declare it, one is drawn at random on first launch and written into the data directory: as long as that volume persists, all is well. The day the volume is recreated, the key changes — and you get access denied with perfectly valid credentials, a misleading symptom that sends people hunting through passwords. The same key also encrypts stored secrets (OAuth tokens, API credentials): losing it does not merely drop sessions, it makes those secrets unreadable. Generate it once with openssl rand -hex 32, put it in your environment file, and treat it as a production secret. If you run several instances behind a load balancer they must all carry the same value, otherwise a token issued by one is rejected by another.

Configuring multi-user access

Open WebUI includes a built-in account and role system that lets several team members share the same instance. By default, the first account created becomes the admin. Subsequent users are placed in a pending queue if you have enabled registration moderation — a recommended option to prevent a port 3000 exposed to the internet from being open to anyone.

Three access levels are available: admin (full access to configuration, models and accounts), user (access to chats and shared assistants) and pending (access blocked until manual approval). To configure moderation:

1. Log in as admin.
2. Go to Settings → Administration → Users.
3. Enable « Sign up with admin approval ».

You can also create assistants (model presets and system instructions) and share them with the whole instance or specific groups, without users having to reconfigure their session.

Troubleshooting: common problems

The container keeps restarting. Check the logs: docker logs open-webui. The most common cause is a missing or malformed WEBUI_SECRET_KEY — the variable must be a non-empty hexadecimal string. If it is generated at launch without being persisted in a volume or a .env file, it changes on every container restart.

Ollama connection fails ("Could not connect to Ollama"). The default URL http://localhost:11434 does not work from inside a Docker container: localhost refers to the container itself, not the host. Use http://host.docker.internal:11434 (on Linux: add --add-host=host.docker.internal:host-gateway to the docker run command) or run both containers in the same Docker network and reference the Ollama container by its name.

502 Bad Gateway after the reverse proxy. The Nginx proxy points to port 3000 but Open WebUI listens internally on port 8080 — the docker run command maps 3000:8080. Make sure your vhost points to http://127.0.0.1:3000, not 8080.

WebSocket disconnecting (interface freezing). The Upgrade and Connection headers are essential for the WebSockets the interface relies on. Check that your proxy_set_header block includes both.

If you want to run an Ollama model directly on the same VPS, opt for a plan with at least 8 GB of RAM and SSD storage to reduce model loading times.

The Official Documentation

For advanced configuration, tool-specific options and version changes, refer to the official Open WebUI documentation. This guide covers going live on a ServOrbit VPS; the vendor's documentation remains the reference for fine-tuning.

Deploy your Open WebUI environment in just a few minutes.

Order a ServOrbit Cloud VPS and choose the Artificial Intelligence template during setup. Your environment is installed automatically.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab