All guides
Getting started
VPS
- VPS operating systems
- VPS snapshots and
off-site backups - How to host your own VPN on a VPS with WireGuard
- How to run a Tor relay, bridge or onion service on a VPS
- How to
self-host BTCPay Server on a VPS - How to run a Bitcoin or Monero node on a VPS
Dedicated servers
- Using IPMI and the KVM console on a dedicated server
- Choosing a RAID layout for your dedicated server
Windows RDP
Windows Server 2019 , 2022 or 2025 vsWindows 10 and 11 for RDP- How to connect to a Windows RDP server from any device
GPU servers
Security
On this page
- BTCPay Server requirements and the right plan
- Why
self-host BTCPay Server on a VPS - What an offshore,
no-KYC host changes, and what it does not - How to
self-host BTCPay Server,step by step - Keep it running: updates, backups and disk space
- Secure BTCPay Server and your wallet
- Email notifications and
port 25 - Frequently asked questions
To
These steps use an Offshore VPS with btcpay.example.comSERVER_IP
BTCPay Server requirements and the right plan
The official Docker deployment runs BTCPay Server, PostgreSQL, NBXplorer, Bitcoin Core, Nginx with automatic HTTPS and Tor on one machine. A BTCPay Server pruned node downloads and checks every block but keeps only recent ones, up to its profile's target. BTCPay's server specifications size the disk as
| Setup | Pruning profile (blocks kept) | Disk by BTCPay's formula | Plan that fits | Price |
|---|---|---|---|---|
| Test, Bitcoin only | opt-save-storage-xxs | Sloop: | $3.49 | |
| Shop, Bitcoin only (BTCPay's starting point) | opt-save-storage-xs | Cutter: | $5.49 | |
| Bitcoin and Lightning | opt-save-storage-s | Schooner: | $12.49 | |
| Lightning, busier stores | opt-save-storage | Brigantine: | $19.99 | |
| Bitcoin and Monero | Bitcoin as above; Monero pruned by default | Frigate: | $47.99 | |
| Unpruned node | None | About | Dedicated server, | From $97.49 |
These are bare figures: BTCPay says to add headroom, and each plan here has at least
When you need an unpruned node
Transaction indexing (opt-txindex
BTCPay Lightning: Core Lightning, LND or Phoenixd
Lightning is optional: BTCPAYGEN_LIGHTNINGclightninglndphoenixd
Why self-host BTCPay Server on a VPS
BTCPay Server hosting takes three forms: a
What an offshore, no-KYC host changes, and what it does not
What changes: our account is an email address and a password, nothing else, and you pay from your own wallet in Bitcoin, Ethereum, Monero, Tether (USDT) or Solana, with no card or ID. A
- Your IP address and hostname are public: every customer who opens an invoice connects to them.
- Bitcoin is public: each invoice gets a new address, but amounts and timing stay on the blockchain.
- Buyer details your checkout collects sit in your database, under the privacy law that applies to your business.
- The law still applies: taxes, consumer and payment rules where you trade, and the server country's law, including the
Digital Services Act in our EU locations. - Our acceptable use policy applies: fraud against real people, such as fake shops and carding, is
zero-tolerance . - Tor is not anonymity: the deployment adds an onion address, which BTCPay's FAQ says "doesn't make you anonymous at all".
How to self-host BTCPay Server, step by step
1. Point a domain at the server
At your DNS provider, create an A record for a hostname such as btcpay.example.comSERVER_IP
getent ahostsv4 btcpay.example.com
2. Open the firewall
Allow SSH first (your own port if you changed it), then HTTP, HTTPS and, for Core Lightning or LND, 9735:
apt update
apt install -y ufw git
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw allow 9735/tcp
ufw enable
Docker's published ports bypass UFW through Docker's own NAT rules, so UFW cannot hide BTCPay, but it protects everything else. Do not use an nftables file with flush ruleset
3. Clone the repository and set the variables
Work in a root login shell, as the README does: log in as root, or run sudo su -
mkdir BTCPayServer
cd BTCPayServer
git clone https://github.com/btcpayserver/btcpayserver-docker
cd btcpayserver-docker
export BTCPAY_HOST="btcpay.example.com"
export NBITCOIN_NETWORK="mainnet"
export BTCPAYGEN_CRYPTO1="btc"
export BTCPAYGEN_LIGHTNING="none"
export BTCPAYGEN_REVERSEPROXY="nginx"
export BTCPAYGEN_ADDITIONAL_FRAGMENTS="opt-save-storage-xs"
. ./btcpay-setup.sh -i
- BTCPAY_HOST
- Your hostname; setup rejects anything that is not a valid domain name.
- NBITCOIN_NETWORK
, ormainnet to experiment.testnet- BTCPAYGEN_CRYPTO1
;btc adds Monero.BTCPAYGEN_CRYPTO2="xmr"- BTCPAYGEN_LIGHTNING
,none ,clightning orlnd .phoenixd- BTCPAYGEN_REVERSEPROXY
, which obtains and renews the HTTPS certificate.nginx- BTCPAYGEN_ADDITIONAL_FRAGMENTS
- Separated by semicolons, with one pruning profile; setup refuses
next to one. When you change the list later, include the profile again, or pruning turns off and the node stops with "Block files have previously been pruned".opt-txindex - BTCPAY_ENABLE_SSH
- Found in older guides; the current script ignores it.
4. Run the setup script
Keep the leading dot: the script must be sourced, and without -i-i/etc/profile.d/btcpay-env.shbtcpayserver
5. Register the admin account at once
Open https://btcpay.example.com
6. Let the node sync
The site opens before the first sync ends, which BTCPay's synchronization FAQ puts at one to five days. Check progress with:
bitcoin-cli.sh getblockchaininfo
The node is synced when blocksheadersinitialblockdownloadfalse
7. Create a store and connect a wallet
Registration leads to store creation: a name, a default currency and a rate provider. Then connect the store's wallet, in the order of BTCPay's wallet guide:
- A hardware wallet through the BTCPay Server Vault app, or a wallet file from Electrum or Wasabi.
- An xpub, typed in or scanned as a QR code.
- Never the seed: "you should never type wallet seed words on any internet connected device."
BTCPay uses a new address for every invoice, while most wallets watch only about 20 unused addresses, the gap limit: after a run of unpaid invoices, raise it (Electrum, Sparrow and Bitcoin Core allow this), or payments seem to go missing.
Keep it running: updates, backups and disk space
Updates
Update in a root login shell, or with Update under Server Settings > Maintenance:
btcpay-update.sh
The update pulls the repository, regenerates the stack, recreates the containers, then deletes every unused Docker image on the host, BTCPay's or not, unless BTCPAY_UPDATE_CLEAN
Backups
cd "$BTCPAY_BASE_DIRECTORY/btcpayserver-docker"
./btcpay-backup.sh
The backup script dumps the databases, stops the stack, archives the Docker volumes, secrets and dumps, then restarts. It skips blockchain data, caches, logs and LND's channel database, and keeps LND's wallet and channel.backup/var/lib/docker/volumes/backup_datadir/_data/backup.tar.gz, is overwritten at each run and stays on the server: set BTCPAY_BACKUP_PASSPHRASE
SHELL=/bin/bash
PATH=/bin:/usr/sbin:/usr/bin:/usr/local/bin
15 4 * * * /root/BTCPayServer/btcpayserver-docker/btcpay-backup.sh
Restore with ./btcpay-restore.sh
Lightning needs more: BTCPay warns that "broadcasting a revoked state can cause you to lose all funds in that channel." With LND, keep the seed from Server Settings > Services > LND Seed Backup and an channel.backupbtcpay-down.shbtcpay-up.sh
Disk space and sync status
A full disk stops Bitcoin Core, and BTCPay then shows the node as always starting. Check with:
df -h /var/lib/docker
docker system df
bitcoin-cli.sh getblockchaininfo
With pruning, size_on_disk
Secure BTCPay Server and your wallet
- Registration stays off; invite other users from Server Settings.
Two-factor authentication: turn it on in your account settings (authenticator app or U2F key). If you lose the device, root can remove it with./btcpay-admin.sh disable-multifactor YOUR_ACCOUNT_EMAILin the repository folder, per the server settings FAQ.- SSH: log in with keys, as in the hardening guide. Setup adds a restricted root key for the Maintenance actions and may change
toPermitRootLogin no inprohibit-password . In our test, the hardening guide's file, read first, kept root refused, so BTCPay hides those actions. Update from the shell, or set/etc/ssh/sshd_configPermitRootLogin forced-commands-onlyin that file, which admits root only with a forced command, and add toroot .AllowUsers - No seed on the server. On a KVM host, the provider can technically read a VPS's disk and memory. With a hardware wallet or an xpub, an intruder or the host could watch your payments but not spend them. A BTCPay hot wallet and an internal Lightning node hold private keys: keep only working balances there.
Email notifications and port 25
BTCPay can email password resets, invitations and store events such as a settled invoice, over SMTP set under Server Settings > Email server or in a store's settings. Without SMTP, its notifications guide says, there is "no easy way" to reset a password. Our network closes outbound
Frequently asked questions
How much does it cost to self-host BTCPay Server?
The software is free, with no subscriptions or transaction fees; you pay for the server and a domain. BTCPay's starting point (
Can I run BTCPay Server on a 2 GB VPS?
Only as a test. BTCPay's deployment FAQ lists opt-save-storage-xxs
Do I need a full Bitcoin node for BTCPay Server?
You need a validating node, not the whole chain on disk. The deployment's Bitcoin Core checks every block, and a pruning profile keeps
Can I host BTCPay Server without KYC?
Yes. BTCPay is software you run yourself, with no account to open, and our hosting needs only an email address and a password, with payment in Bitcoin, Ethereum, Monero, Tether or Solana. Your domain registrar and mail provider have their own rules, and taxes, consumer law and our acceptable use policy still apply.
Does BTCPay Server support Monero?
Yes, through the community-maintained Monero plugin. Set BTCPAYGEN_CRYPTO2="xmr"
Dedicated and GPU customers can open a ticket from the client area with the server’s IP address and what they tried. First reply target: under