Independent research for creator workflowsOfficial sources & verified limits. How we review

Self-hosting

Self-host LiteLLM on a VPS with Docker

LiteLLM is free to self-host, but only while a server keeps it running. This guide takes the official Docker quick start and turns it into an always-on gateway on a small Linux VPS, with the security steps the quick start leaves to you.

Platform
LiteLLM
Best for
Developers and platform teams who want a self-hosted, free AI gateway with granular spend control, virtual keys, and fallbacks — without per-token platform fees.
Hands-on
Controlled benchmark pending

PremiumPeek · Self-hosting

How to Self-Host LiteLLM on a VPS (Docker Guide)

Run the free LiteLLM AI gateway 24/7 on your own VPS: Docker Compose setup, master and salt keys, locking down port 4000, updates, and supply-chain safety.

  1. 01Start the stack
  2. 02Add one model
  3. 03Issue a virtual key
  4. 04Check exposure

Quick answer

Use the official Docker Compose quick start (LiteLLM plus PostgreSQL) on any Linux VPS that runs Docker, set a long random master key and salt key, keep port 4000 closed to the public internet unless you put it behind HTTPS and authentication, pin the image version, and update deliberately. The software is free; the VPS is your fixed monthly cost.

Starting point: Open source and self-hosted is free forever ($0): 100+ providers behind one OpenAI-compatible API with... · Free tier: Free tier available

This evaluation is built on verified documentation and official pricing data, paired with a repeatable test workflow you can run directly in your own project.

Worth evaluating when

  • Developers who already use LiteLLM locally and need it available to scripts, agents or teammates around the clock
  • Small teams that want virtual keys, budgets and spend tracking without a per-token platform fee
  • Anyone replacing a hosted gateway with a fixed-cost server they control

Check before paying

  • You own uptime, backups and upgrades; there is no vendor SLA on the open-source edition
  • Supply-chain risk: litellm 1.82.7 and 1.82.8 on PyPI shipped credential-stealing malware on March 24, 2026 (advisory BerriAI/litellm #24518); pin versions and verify before upgrading
  • An exposed gateway spends your provider credit: never publish port 4000 without authentication and HTTPS

Why run LiteLLM on a VPS

LiteLLM puts 100+ model providers behind one OpenAI-compatible API with virtual keys, budgets, rate limits, fallbacks and spend tracking. The open-source edition is free, but it is a server: when your laptop sleeps, every script, agent and teammate pointed at it stops working.

A small Linux VPS keeps the gateway online for a fixed monthly price. You pay your model providers directly, and LiteLLM adds no per-token markup, which is the main reason teams choose it over a hosted gateway such as OpenRouter.

What you need

Any Linux VPS that can run Docker and Docker Compose. LiteLLM's Compose quick start runs two containers: the gateway and a PostgreSQL database that stores models, keys and spend logs. Start with a small plan, watch memory use under your real traffic, and upgrade only if you add many users, logging volume or Redis.

You also need at least one model provider API key (for example OpenAI or Anthropic), a way to generate long random secrets (openssl is preinstalled on most distributions), and ideally a domain name if the gateway must be reachable from outside the server.

Install with the official Docker Compose quick start

LiteLLM's documentation provides a Compose file for the quick start. On the server, download it and create a.env file with two long random secrets: curl -sSLO https://github.com/BerriAI/litellm/raw/main/docker/docker-compose.quickstart.yml, then printf 'LITELLM_MASTER_KEY=sk-%s\nLITELLM_SALT_KEY=sk-%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" >.env, then docker compose -f docker-compose.quickstart.yml up -d.

This starts the gateway on port 4000 together with PostgreSQL. The master key authenticates admin requests; the salt key encrypts stored provider credentials, so store it safely and do not change it after you add models, or stored keys can no longer be decrypted.

If you prefer a single container without a database, the documentation also shows docker run with a mounted config.yaml, your provider key as an environment variable and -p 4000:4000. That is fine for testing, but you lose persistent virtual keys and spend logs.

Lock it down before you rely on it

Do not expose port 4000 directly to the internet. Either keep it bound to localhost and reach it over an SSH tunnel or private network, or put it behind a reverse proxy (Caddy or Nginx) that terminates HTTPS on your domain.

Use the firewall on the VPS to allow only SSH and HTTPS. Issue virtual keys with budgets to each script or teammate instead of sharing the master key, so one leaked key cannot drain your provider credit.

Keep provider API keys in the.env file or LiteLLM's database, never in a public repository, and back up the PostgreSQL volume together with the salt key.

Updating safely

Pin the image to a specific version instead of a moving latest tag, read the release notes, then update with docker compose pull followed by docker compose up -d. Take a database backup first.

Treat upgrades as a supply-chain decision. The March 2026 PyPI incident (versions 1.82.7 and 1.82.8) shows why: follow the official advisory, avoid installing unreviewed releases the day they appear, and verify what you run.

When a hosted gateway is the better choice

If you do not want to maintain a server, a hosted gateway such as OpenRouter trades a fee on credit purchases for zero operations. If you want free-tier provider pools for personal use, OmniRoute is another self-hosted option. The OpenRouter vs LiteLLM comparison covers the trade-off in detail.

Run it 24/7 on your own server

LiteLLM runs on your own machine, so it stops answering when your laptop sleeps. A small Linux VPS with Docker keeps it online for scripts, agents and teammates, with a fixed monthly cost instead of per-token markup.

  • Start with the smallest plan that runs Docker; upgrade only if you add users or local models.
  • Keep the gateway bound to localhost or behind a firewall, and store provider keys as environment variables.
  • Monthly billing lets you test before committing to a long term.

Some links are affiliate links. We may earn a commission if you buy through them. Payment never changes our rankings or editorial verdicts.

Related comparisons

Compare LiteLLM against the tools creators most often weigh it against.

Run a same-input test

  1. Start the stack

    Run the Compose quick start and confirm both the gateway and database containers are running with docker compose ps.

  2. Add one model

    Add a model with your provider key through the admin UI or config, then send a single chat completion to http://localhost:4000 using the master key.

  3. Issue a virtual key

    Create a virtual key with a small budget and repeat the request with it to confirm spend is tracked against that key.

  4. Check exposure

    From another machine, confirm port 4000 is not reachable directly and that access only works through your SSH tunnel or HTTPS proxy.

  5. Rehearse an update

    Back up the database, change the pinned image version, run docker compose pull and up -d, and confirm keys and spend logs survived.

Official sources

Frequently asked questions

Is LiteLLM free to self-host?

Yes. The open-source gateway is free; you pay for the server and for your model providers' usage. LiteLLM's paid Enterprise edition adds SSO, audit logs and support and is priced by request capacity, not per token.

Which port does LiteLLM use?

The Docker quick start serves the gateway on port 4000. Keep it private or behind an HTTPS reverse proxy with authentication.

Do I need PostgreSQL?

For virtual keys, budgets and spend logs, yes: the official Compose quick start includes it. A single container with a config file works for quick tests without persistence.

Is LiteLLM safe after the March 2026 PyPI incident?

The compromised releases were litellm 1.82.7 and 1.82.8 on PyPI, live for about 40 minutes on March 24, 2026. Follow the official advisory (BerriAI/litellm issue #24518), pin versions and verify releases before upgrading.

Related workflows