An onion service (the thing behind a .onion address) lets people reach a site on your VPS through the Tor network without the site ever exposing its IP address or needing a domain, a public port or a TLS certificate. The reachability comes from Tor, not from a special server: any VPS with root runs one. Below is the whole setup on a Linux VPS with nginx — the web server on localhost, Tor in front of it, and the one rule that still applies: our Acceptable Use Policy governs what the site may host, the same on a .onion as on the open web.
What an onion service is, and is not
- It hides the server’s location from visitors, and visitors’ from the server: the connection is end-to-end inside Tor, so neither side learns the other’s IP address.
- It needs no domain and no open port. The address is derived from a key pair Tor generates; nothing listens on a public interface.
- It is not anonymity for whatever you host. A misconfigured app that leaks its real hostname, an analytics script that phones home, or a server that also answers on its public IP undoes it. And it does not place the content outside the law or outside our AUP — it changes how people reach the site, not what the site is allowed to be.
A web server bound to localhost
Install nginx and keep it off every public interface. Tor talks to it over the loopback address only, so nothing has to be reachable from the internet.
sudo apt update && sudo apt install -y nginx
# serve the site on localhost only
sudo tee /etc/nginx/sites-available/onion >/dev/null <<'EOF'
server {
listen 127.0.0.1:80;
server_name localhost;
root /var/www/onion;
index index.html;
}
EOF
sudo mkdir -p /var/www/onion
echo '<h1>It works over Tor.</h1>' | sudo tee /var/www/onion/index.html >/dev/null
sudo ln -sf /etc/nginx/sites-available/onion /etc/nginx/sites-enabled/onion
sudo rm -f /etc/nginx/sites-enabled/default
sudo nginx -t && sudo systemctl reload nginxInstall Tor and declare the service
Install Tor from your distribution, then add two lines to torrc. They name a directory for the service’s keys and map the onion’s port 80 to the nginx instance on localhost.
- 1Install Tor
Debian · Ubuntu sudo apt install -y tor - 2Declare the onion service in /etc/tor/torrc
/etc/tor/torrc HiddenServiceDir /var/lib/tor/onion/ HiddenServicePort 80 127.0.0.1:80 - 3Restart Tor and read the address
sudo systemctl restart tor sudo cat /var/lib/tor/onion/hostname
The hostname file holds your address — 56 characters followed by .onion, a version-3 onion service. Open it in the Tor Browser and the nginx page answers. The keys in HiddenServiceDir are the identity of that address: back them up, keep them to 0700 owned by the Tor user, and anyone who copies them can impersonate your service.
Keep it from leaking
- One job per server, ideally. If the VPS also serves a clearnet site or answers SSH on its public IP, that traffic still identifies the machine. The onion service hides nothing the rest of the server advertises.
- Strip absolute URLs. Links and redirects that point at a real domain or the server’s IP pull visitors off Tor. Serve relative links, and set nginx’s
absolute_redirect offif it rewrites them. - No third-party scripts. Fonts, analytics and CDN assets loaded from the open web defeat the point and often break in the Tor Browser anyway. Host what the page needs on the server.
- Set
HiddenServiceVersiononly if you know why. Tor builds v3 services by default now; the old v2 addresses are gone.
Which VPS, and what is allowed
A static site or a small app over Tor needs very little: the entry Standard KVM plan, €4.99 a month in Amsterdam for 2 vCores and 4 GB, is plenty, and you can pay in Monero or another coin with no ID check — Crypto VPS shows how. Tor itself is light; the web app behind it sets the size.
An onion service does not change our rules. Everything the Acceptable Use Policy forbids on the open web — malware, phishing, fraud, spam and CSAM — is forbidden on a .onion too, and a lawful order from an authority with jurisdiction over the server is answered. What the line DMCA Ignored KVM changes is only how US copyright notices are handled; it is not a shelter for anything the AUP prohibits. If you want to contribute capacity to the network instead of hosting a site, a Tor relay on a VPS is the other side of this, and running a Monero node is a related privacy-infrastructure job.
Frequently asked
How do I host a website as a Tor onion service?
Run a web server such as nginx bound to 127.0.0.1, install Tor, and add two lines to /etc/tor/torrc: 'HiddenServiceDir /var/lib/tor/onion/' and 'HiddenServicePort 80 127.0.0.1:80'. Restart Tor and read the .onion address from /var/lib/tor/onion/hostname. No domain, public port or TLS certificate is needed.
Does an onion service make my site anonymous or untouchable?
No. It hides the server's IP from visitors and the visitors' from the server, but a leaky app, a third-party script, or the same server answering on its public IP undoes that. It also does not place the content outside the law or outside the Acceptable Use Policy — it changes how people reach the site, not what the site may host.
Which VPS do I need for an onion service?
A small one. Tor itself is light, so the entry Standard KVM plan — €4.99 a month in Amsterdam for 2 vCores and 4 GB — runs a static site or a small app over Tor comfortably; the web app behind Tor, not Tor, sets the size. You can pay in Monero or another coin with no ID check.