Server & LLM box
Set up a Mac mini to run AI agents around the clock
A Mac mini has become the default home for personal AI agents like OpenClaw and for coding agents like Claude Code left running overnight. It is quiet, draws a few watts at idle, and runs full macOS, so an agent can use Messages, Notes, Shortcuts and a real browser. Installing the agent takes minutes. Keeping it answering after a reboot, a power cut or a macOS update is the actual work, and that is what this guide covers.
Which Mac mini, and how much memory
If the agent calls a cloud model such as Claude or GPT, the Mac is only a host: 16 GB is plenty and the base model is the right buy. If it also runs a local model, memory decides what fits: 24 to 32 GB for a mid-sized model next to the agent, 48 to 64 GB before large models feel usable.
Use Ethernet rather than Wi‑Fi for a machine you will reach remotely, and leave room on the disk for logs, browser profiles and model files, which grow faster than you expect.
Power is not a worry. Apple rates recent Mac minis at about 4 to 6 watts idle, less than an LED bulb left on around the clock.
Give the agent its own account
- Create a standard, not administrator, user for the agent under System Settings → Users & Groups, and do the rest of this setup logged in as that user.
- If the agent will use Messages or iCloud, sign that user in to a separate Apple Account, so it never sees your personal Keychain, photos or mail.
- Keep API keys in that account only, and set a spending limit with each provider. An agent stuck in a loop can spend a month’s budget overnight.
- For OpenClaw, run
openclaw security auditafter setup and after upgrades. The gateway listens only on the Mac itself by default; keep it that way and reach it through a private network.
Sandboxing is off by default in OpenClaw, and anything the agent can read, a prompt injection can read too. Give the account only the folders and permissions its tasks need.
Keep it awake, and bring it back after a power cut
Under System Settings → Energy, turn on “Prevent automatic sleeping when the display is off”, “Wake for network access” and restart after a power failure. In Terminal, sudo pmset -a sleep 0 autorestart 1 womp 1 does the same. The display can still sleep; the agent does not need a lit screen.
pmset -g assertions shows what is holding the Mac awake, the quickest check that your settings took. The power-cut side, including the UPS catch, has its own guide: make a Mac mini turn itself back on after a power failure.
SideMini’s Server mode applies these settings in one step and puts your old ones back with one click.
The reboot problem: FileVault and login
This is where most agent boxes fail. The OpenClaw gateway installs as a LaunchAgent, Claude Code runs in a terminal or tmux session, and the Ollama and LM Studio apps are login items. All of them start only when a user logs in. A Mac that restarts after a power cut or an update and sits at the login window runs none of them.
There are three ways through. Turn FileVault off and set the agent’s user to log in automatically under Users & Groups. Or keep FileVault and, on Apple silicon with macOS 26 or later, unlock it over SSH after a restart, as long as Remote Login was on beforehand; the Mac then boots, but you still need to log the agent’s user in, for example over Screen Sharing. For restarts you plan, sudo fdesetup authrestart unlocks the next boot once.
Choose deliberately. A machine holding your messages and API keys is exactly what FileVault is for; FileVault vs automatic login sets out the trade-off.
Start the agent by itself, and again when it dies
OpenClaw: openclaw onboard --install-daemon installs the gateway as a LaunchAgent at ~/Library/LaunchAgents/ai.openclaw.gateway.plist, logging to ~/Library/Logs/openclaw/. openclaw gateway status --deep and openclaw health tell you whether it is really up. If a restart leaves it unloaded, launchctl bootstrap gui/$UID ~/Library/LaunchAgents/ai.openclaw.gateway.plist loads it again.
Claude Code: run it inside tmux so it outlives your SSH session, and start that from a LaunchAgent with KeepAlive so a crash brings it back. For unattended one-off jobs, claude -p with an explicit permission mode avoids prompts nobody is there to answer. Remote Control lets you drive the session from your phone over outbound HTTPS only, with no open ports; it needs a Pro or Max plan.
Local models: Ollama listens on 127.0.0.1:11434 and unloads a model after five idle minutes by default; raise OLLAMA_KEEP_ALIVE if the agent calls it rarely and you want fast answers. Ollama recommends a context window of at least 64k tokens for agent work. Serving it to the rest of the network is covered in running Ollama on a Mac mini 24/7.
The permissions that stop an unattended agent
Agents that read messages, control apps or look at the screen need Full Disk Access, Automation, Accessibility or Screen Recording. macOS grants these to the specific process that asked: a permission given to Terminal does not cover the same tool started by launchd or over SSH. Trigger each prompt once from the context the agent will actually run in, then approve it.
OpenClaw’s iMessage channel needs Messages signed in plus Full Disk Access and Automation for that process; computer use needs Accessibility, Screen Recording and a logged-in, unlocked desktop. After a macOS or agent update, check System Settings → Privacy & Security before you walk away.
A screen for a Mac that has none
Screen Sharing to a Mac mini with nothing plugged in shows a blank or low-resolution desktop, and an agent that takes screenshots or drives apps sees the same thing. An HDMI dummy plug or a virtual display gives macOS a proper screen to draw on; the blank Screen Sharing page compares the options.
SideMini gives the Mac a sharp Screen Sharing desktop at 1080p, 1440p or 4K with nothing in the HDMI port, and with an iPad beside it, the iPad becomes its screen whenever you want to look.
Reach it from anywhere, safely
Turn on Remote Login and Screen Sharing under System Settings → General → Sharing, and test both from another device before the Mac goes on a shelf.
Use Tailscale or a similar private network rather than forwarding ports. Only Tailscale’s open-source tailscaled build runs before anyone logs in; the App Store and standalone apps start with a user session, which matters when the Mac is waiting at the login window.
Updates and monitoring
Turn off automatic installation of macOS updates under General → Software Update, and update by hand when you can check that the agent comes back. Agent upgrades break things too: after an OpenClaw, Node or Claude Code update, check the service status and the log.
Have the agent, or a small script, message you when it has not checked in for a while, and watch free disk space: logs and browser caches fill a small SSD faster than models do.
Before you leave it alone
- A standard user for the agent, with its own Apple Account and a spending limit on every API key.
- Never sleep, restart after a power failure, wake for network access.
- A FileVault and login plan you have tested with a real restart.
- The agent starting on its own and coming back after a crash, with its permissions granted to the process that runs it.
- SSH and Screen Sharing working through a private network, with a real screen for Screen Sharing to show.
- One pulled-plug test, checked from your phone.
Sources
- Apple — Mac mini power consumption and thermal output ↗
- OpenClaw — Gateway security ↗
- Apple — Change Energy settings on a Mac desktop computer ↗
- Apple Platform Security — Managing FileVault in macOS ↗
- Apple — Set your Mac to log in automatically (FileVault note) ↗
- OpenClaw — The gateway on macOS ↗
- Claude Code — Remote Control ↗
- Ollama — FAQ ↗
- OpenClaw — iMessage setup ↗
- Tailscale — The three Tailscale clients for macOS ↗