Own the address keys
Generate the onion private keys inside a controlled environment and keep secure offline backups. Losing them means losing the address.
Run your site, API, file drop or administrative endpoint as a v3 onion service. The VPS supplies the machine; you choose the application, hold the onion keys and maintain the configuration.
An onion service makes an application reachable through Tor without publishing a conventional destination address. It is different from operating a relay. Protect the application, onion identity keys and management path, and consider client authentication when the service should be restricted to selected users.
A Tor onion service exposes an application through an authenticated .onion address instead of relying on a public DNS name. Tor builds introduction and rendezvous connections so visitors do not receive the service’s ordinary IP address through that connection.
The underlying machine still has a network allocation. An app binding to a public interface, a link to clearnet resources, a misconfigured mail service or identifiable content can reveal information Tor’s transport does not hide. Protect the entire application rather than only its entry URL.
Generate the onion private keys inside a controlled environment and keep secure offline backups. Losing them means losing the address.
Publish a static site, private cloud, Matrix endpoint, internal dashboard or SSH service without inheriting a shared platform’s app list.
Public onion services are reachable by anyone who knows the address. Tor client authorization can restrict a private service.
You own updates, permission checks, backups and recovery. A VPS does not provide automatic application hardening.
Run the application on a loopback address such as 127.0.0.1. Keep unintended public listeners closed.
Install the maintained Tor package and configure HiddenServiceDir and HiddenServicePort to map the onion port to the local application.
Restrict permissions on the key directory, restart Tor, verify the generated address and test access from a separate Tor client.
Back up keys and application data securely. Confirm that the restored instance uses the intended identity without exposing old copies.
An onion service protects its transport endpoint. The hosting relationship, payment and management path are separate. A pseudonymous account and an onion SSH endpoint can reduce some identifiers; payment transactions on the supported networks remain publicly inspectable.
Do not treat a cloud VPS as a universal replacement for specialist whistleblower infrastructure. Projects such as SecureDrop have specific operational requirements. Follow the application’s own deployment model when people’s safety depends on it.
Monthly or annual billing, with 30% off the twelve-month total when you pay yearly. Prices are in USD; cryptocurrency amounts depend on the invoice exchange rate. Full root, KVM virtualization, NVMe, IPv4 and IPv6 are part of the target specification for every tier.
$13/month · $109.20/year. 1 vCPU, 2 GB RAM, 30 GB NVMe and 2 TB monthly transfer. A compact starting point for one lightweight service.
$33/month · $277.20/year. 2 vCPU, 4 GB RAM, 80 GB NVMe and 4 TB monthly transfer. More room for applications and everyday self-hosting.
$63/month · $529.20/year. 4 vCPU, 8 GB RAM, 160 GB NVMe and 8 TB monthly transfer. Space for a larger stack or transfer-intensive workload.
$118/month · $991.20/year. 8 vCPU, 16 GB RAM, 320 GB NVMe and 16 TB monthly transfer. The largest configuration for dense services and heavier compute.
Choose the resources you need. Keep the personal details you don’t need to share.