aihomelabprivacy

Self-host Claude Code agents with OtoDock

🤖 Researched and drafted automatically from the official docs, and reviewed before publishing. Commands are taken from the source projects — but always sanity-check before running anything on your own hardware.

OtoDock lets you run Claude code agents on your own server instead of sending everything to Anthropic’s infrastructure. You get full control over execution, data stays local, and you avoid per-request SaaS costs. This guide walks you through deploying OtoDock on bare metal or in a VM.

Prerequisites

  • A Linux server (Ubuntu 22.04 LTS or later recommended) or bare metal machine with at least 4 CPU cores and 8 GB RAM
  • Docker and Docker Compose installed
  • An Anthropic API key (you’ll still use Claude’s model API, but code execution runs locally)
  • SSH access to your server
  • The server on your LAN or behind a VPN—never expose this to the public internet

Step 1: Clone the OtoDock repository

SSH into your server and grab the latest OtoDock code:

git clone https://github.com/otodock/otodock.git
cd otodock

Check the repo for any branch or tag you should use. The default branch typically contains the stable release.

Step 2: Review the configuration

OtoDock uses environment variables and a Docker Compose setup. Look at the provided example configuration:

ls -la
cat docker-compose.yml

The compose file defines the OtoDock service, any dependencies (like a code execution sandbox), and networking. Review it to understand what ports and services will run.

Step 3: Set up environment variables

Create a .env file in the OtoDock directory with your Anthropic API key and any local configuration:

cp .env.example .env
# Edit .env with your text editor
nano .env

Add your Anthropic API key:

ANTHROPIC_API_KEY=sk-ant-...

Do not commit this file to version control. Keep it local and secure.

Step 4: Build and start the OtoDock container

Bring up the services with Docker Compose:

docker-compose up -d

Check that the containers are running:

docker-compose ps

You should see the OtoDock service and any supporting services (sandbox, executor, etc.) in the Up state.

Step 5: Verify the service is running

Check the logs to confirm OtoDock started without errors:

docker-compose logs -f otodock

Look for messages indicating the service is listening on a local port (commonly localhost:8000 or similar, depending on the config). Once you see a “ready” or “listening” message, press Ctrl+C to exit the logs.

Step 6: Test a simple agent request

From your server or a machine on the same LAN, test OtoDock with a curl request. Replace localhost with your server’s LAN IP if testing from another machine:

curl -X POST http://localhost:8000/api/agents \
  -H "Content-Type: application/json" \
  -d '{
    "prompt": "Write a Python function that returns the sum of two numbers.",
    "model": "claude-3-5-sonnet-20241022"
  }'

You should receive a response with the generated code and execution results. If you get a connection error, double-check that the container is running and the port is correct.

Step 7: Integrate OtoDock into your workflow

OtoDock exposes an API for agent creation and code execution. Use it from your applications, automation scripts, or n8n workflows:

  • Direct API calls: POST to the agent endpoint with a prompt and model name
  • SDK integration: If OtoDock provides a Python or Node.js client, install it via pip or npm and use it in your scripts
  • Webhook triggers: Set up n8n or other automation tools to call OtoDock endpoints on events

Refer to the official OtoDock docs for the full API specification and SDK examples.

Step 8: Secure your deployment

Since OtoDock runs code locally, it’s critical to isolate it:

  • Network: Keep OtoDock on your LAN only. Do not port-forward or expose it to the internet.
  • Firewall: Use ufw or your firewall to allow only trusted IPs to reach OtoDock’s port.
  • Reverse proxy: If you need remote access, put OtoDock behind a VPN (WireGuard, Tailscale) or an authenticated reverse proxy (Caddy, Nginx with auth).
  • Container security: Run OtoDock with a non-root user and limit resource quotas in docker-compose.yml.

Step 9: Monitor and maintain

Set up basic monitoring and log rotation:

# View recent logs
docker-compose logs --tail=50 otodock

# Restart if needed
docker-compose restart otodock

# Update to the latest version
cd otodock
git pull
docker-compose down
docker-compose up -d

Check the OtoDock repository regularly for updates and security patches.

Is it worth it?

Yes, if you run code agents frequently and want to avoid SaaS costs and data leakage. OtoDock gives you a self-hosted Claude agent engine that executes code on your hardware. The trade-off is you manage the infrastructure—patching, monitoring, and ensuring it stays behind a firewall. For a homelab or small team, it’s a solid way to keep agent execution private and under your control. You still pay for Claude API calls, but you save the per-execution overhead and keep sensitive code local.

Related guides

← All guides