How to Host Your Own Onion Website Legally (2026 Guide)

People generally imagine onion sites to be mysterious affairs operated by shadowy individuals who work from basements. The truth, however, is quite ordinary: the BBC has one, as do The New York Times, DuckDuckGo, Proton, and a large number of small bloggers, activists, libraries and hobbyists who just want their work to be accessible in a private and censorship resistant way.

Setting up your own onion site is in fact considerably easier than most people expect. If you can follow a few commands and edit a text file, you can have a working site on the Tor network in under an hour. The only cost involved is the computer or server you already own.

This guide covers the entire process, starting with the legal basics and going all the way to a working website, as well as the steps that keep it secure. It’s written for October 2026, which matters more than usual this year: older versions of Tor stopped working on the network in September, and as a result some of the older tutorials still around are now out of date.

Let me make one thing clear: this guide is about hosting legal content. That includes blogs, portfolios, community pages, mirrors of public information, newsletters, documentation and personal projects. If anything of that sort is what you have in mind, carry on.

Why host an onion site at all?

That’s a reasonable question. If you already have a standard website, why bother with an onion one?

Censorship resistance. In countries where websites are blocked, an onion address is much more difficult to take offline, which is why major news organisations maintain onion mirrors.

Privacy for your visitors. Since people visiting your onion site never leave the Tor network, there is no exit relay in the middle, and an internet service provider has nothing to log except that Tor is being used.

No domain name, no registrar and no DNS. The address is derived from a cryptographic key that you create yourself. Nobody can seize your domain name or hijack your DNS, since there isn’t any.

It works behind home routers. Onion services connect outwards to the Tor network, so there is no need to open ports or worry about port forwarding. The site can be hosted on a spare laptop or a Raspberry Pi connected to your home internet.

Built in end to end encryption. Tor itself encrypts the traffic between the visitor and your server, even without an HTTPS certificate.

It’s genuinely interesting. Plenty of people do it just to find out how Tor works from the inside.

Let’s make sure this part is clearly understood before dealing with any software, since it’s where people most often get confused.

Running an onion service is legal in most countries. In the UK, the US, the EU, Canada, Australia and most of the world, using Tor to host a site is entirely lawful. The Tor Project itself publishes official setup guides for onion services, and governments, universities and newsrooms operate them openly.

The law still applies to your content. Using an onion address doesn’t change what you are permitted to publish. If something wouldn’t be legal on a normal website, it isn’t legal on an onion site either.

You’re responsible for what people post. Whenever your site includes comments, a forum, file uploads or anything else that lets visitors add content, you must moderate it. One of the quickest ways to end up hosting something illegal without intending to is running an open upload page on Tor without any moderation.

Data protection still counts. If you gather email addresses, use a contact form or keep records that can identify individuals, laws such as the GDPR in the UK and the EU might apply. The simplest solution for most onion sites is to collect as little data as possible. Since Tor already hides your visitors’ IP addresses from you, you can go a long way without storing any personal data at all.

Check your hosting terms. If you’re using a rented server, look at the provider’s terms of service; most permit Tor onion services, some do not, and a few regard any Tor activity as suspicious. Hosting from home is generally fine, but it’s still worth checking your internet provider’s acceptable use policy as well.

Some countries restrict Tor. A few places, such as China, Russia and Iran, block or restrict Tor, and laws vary around the world. If you’re unsure about the rules where you live, check them first. This guide provides general information only and should not be regarded as legal advice.

The simple rule is this: an onion site is merely a website that is reached in a different way. Treat it with the same level of responsibility as you would any site with your name on it.

What you need before you start

You don’t need much.

A computer that stays on. This might be a rented virtual server, an old laptop, a mini PC or a Raspberry Pi. Your website is only live while this machine is running and connected to the internet.

A Linux system. You can set up onion services on Windows or Mac, but the easiest and best documented route is Linux. This guide uses commands for Debian and Ubuntu, which also work on Raspberry Pi OS.

Basic comfort with the command line. You’ll be installing packages, editing a few text files and restarting services. That’s as far as it goes.

Something to publish. Just one HTML page is enough to get going. You can always expand it later on.

About an hour. Most of that time is spent reading and checking. The actual setup only takes a few minutes.

If all you need is to share a few files or a simple static page for a short time, there’s an even easier choice: OnionShare. It’s a free desktop application that lets you host a small website directly from your computer with a few clicks. It’s excellent for quick, temporary sites, but for anything you want online continuously, a proper setup like the one below is better.

Step by step: setting up your onion site

The concept is simple. You run a normal web server that only responds to requests on your own machine, then you tell Tor to make that web server reachable as an onion service. Tor takes care of the address, the encryption and the connection to the network.

Step 1: Install Tor, and make sure it’s a current version

This is the step where 2026 matters most. The Tor Project ended support for the 0.4.8 series on 1 June 2026 and set 1 September as the date after which versions older than 0.4.9 stop working on the network altogether. If you install an old version of Tor from an outdated package list, your onion service simply won’t come online.

On Debian or Ubuntu, start by updating your system:

sudo apt update
sudo apt upgrade

The version of Tor in your distribution’s own repository may lag behind. For a server, the safest choice is to use the Tor Project’s own package repository, which the Tor Project documents on its support site. Once that’s set up, install Tor:

sudo apt install tor

Then check which version you’ve got:

apt policy tor

You want to see 0.4.9 or newer. If you see 0.4.8 or anything older, don’t continue until you’ve fixed that.

Step 2: Install a web server

You can use any web server you like. Nginx is lightweight and popular, so we’ll use that:

sudo apt install nginx

Create a folder for your site and add a simple page:

sudo mkdir /var/www/onion
sudo nano /var/www/onion/index.html

Put anything you like in the file. Even a line of plain text will do for now.

Step 3: Make the web server listen only on your own machine

This is the most important security step, and the one beginners most often get wrong. Your web server should not be reachable from the public internet at all. Only Tor should be able to talk to it.

Create a new configuration file:

sudo nano /etc/nginx/conf.d/onion.conf

And add this:

server {
    listen 127.0.0.1:8080;
    root /var/www/onion;
    index index.html;
    server_tokens off;
    access_log off;
}

The address 127.0.0.1 means “this machine only”, so nothing outside can connect. Turning off server tokens hides your Nginx version, and turning off the access log means you don’t keep a record of visits you don’t need.

Also disable the default site that comes with Nginx, so it isn’t left listening on your public IP address. Then reload Nginx and check that it’s running without errors:

sudo systemctl reload nginx
sudo systemctl status nginx

Step 4: Tell Tor about your site

Open Tor’s configuration file:

sudo nano /etc/tor/torrc

Add these two lines at the bottom:

HiddenServiceDir /var/lib/tor/my_website/
HiddenServicePort 80 127.0.0.1:8080

The first line tells Tor where to keep your onion service’s keys. The second says that when someone visits your onion address on the normal web port, Tor should pass the connection to your web server on port 8080. Despite the old “hidden service” name in the settings, this creates a modern version 3 onion service by default.

Restart Tor:

sudo systemctl restart tor

Step 5: Find your onion address

Tor has now created a new key pair and your address. You can read it with:

sudo cat /var/lib/tor/my_website/hostname

You’ll see a 56 character address ending in .onion. That’s your site. Open Tor Browser on any device, paste it in, and after a short wait your page should load. The first connection can take a minute while the service is published to the network, so don’t panic if it isn’t instant.

Step 6: Back up your keys

You will also find a file named hs_ed25519_secret_key in that folder. That file is your onion address: anyone who has it can run a site at your address, and if you lose it, your address is lost forever.

Copy the folder to a safe, offline location, for example an encrypted USB stick. Don’t share it, don’t upload it to any cloud storage you don’t control, and don’t commit it to a code repository.

Keeping your onion site safe

Getting a page online is the easy part. Keeping it running safely takes a bit more care, although nothing involved is difficult.

Keep everything updated

By far the most useful habit is to enable automatic security updates for your operating system and to update Tor each time a new version is released. The September 2026 cutoff for older versions was a good reminder that the Tor network keeps moving, and services running outdated software may suddenly stop working.

Switch on denial of service protection

Popular onion sites are sometimes overwhelmed by fake connection requests intended to take them offline. Recent versions of Tor have a defence that relies on a small “proof of work” puzzle, which visitors’ browsers solve automatically whenever a service is under pressure. Ordinary visitors hardly notice it, but it makes flooding attacks much more costly.

You can switch it on by adding one line under your onion service settings in the torrc file:

HiddenServicePoWDefensesEnabled 1

The Tor Project’s guide to onion service DoS defences goes into more detail about this and other options, such as rate limits.

Don’t leak information about your server

The whole idea behind an onion service is that visitors should not be able to see where it is hosted. A number of common mistakes can undo that.

Don’t load anything from the regular web. Fonts from Google, scripts from a CDN, embedded videos and tracking widgets all pull your visitors out of Tor to fetch content, and some can reveal information about your setup. Host every file yourself, on the same machine.

Watch your error pages. The default ones usually display the name and version of the web server, so either customise them or keep them plain.

Check file metadata. The images and documents you publish may include GPS coordinates, author names and device details. Remove this data before uploading; our guide to metadata explains how.

Keep your onion service separate. If a server also hosts a public website on its real IP address, someone may be able to link the two by comparing content, uptime or response times. If it matters that your hosting location stays private, give the onion service its own machine.

Don’t let the server talk to the internet unnecessarily. Scripts that fetch remote content, send emails or call external services could reveal the server’s real address.

If you are seriously concerned about hiding your location, the Tor Project’s operational security guide is well worth reading in full.

Make it private if you need to

Not every onion site needs to be public. If you only want a small number of people to reach it, such as a team wiki or a family photo album, you can use a feature known as client authorisation, now also referred to as restricted discovery. Only people with the correct key can find the service on the network; for everybody else, the site doesn’t exist.

What’s new for onion hosts in 2026

Beyond the 0.4.9 requirement, there has been steady progress this year.

Arti, the Tor Project’s new version of Tor written in Rust, is becoming more capable at hosting onion services. Arti 2.5.1, released in August, allowed onion services to connect to Unix socket addresses and added experimental support for congestion control and the new Counter Galois Onion encryption on onion service circuits. Arti 2.7.0 followed on 1 October. For now, the classic C version of Tor used in this guide remains the most widely used and best documented way to run an onion site, but Arti is clearly where things are heading.

Counter Galois Onion is a new kind of cryptographic protection that the Tor Project is bringing to the entire network to guard against certain types of attack on circuits. You don’t need to do anything to benefit from it other than keeping your software up to date.

Going further

Once the basic version of your site is running, there are some extras worth knowing about.

Adding an onion address to a site you already have

If you already have a normal website, you can also provide an onion version of it, just as the BBC and The New York Times do. The procedure is the same as above, except that Tor points to your existing web server rather than a new one.

Once it’s live, let Tor Browser users know it exists. The simplest method is the Onion Location feature. You add a small header or meta tag to your regular website, and visitors using Tor Browser will see a purple “.onion available” button in the address bar. Clicking it takes them straight to your onion version. It also helps protect them from fake copies, since the address comes from you rather than from a link list.

Do you need HTTPS?

For most onion sites, no. Tor already encrypts the connection all the way from the visitor to your server, and the address itself proves which server they are talking to.

There are, however, situations where HTTPS is still useful. Large websites with complex configurations, those that route traffic between several servers behind the scenes, and organisations that want visitors to see their verified name may all benefit.

As of October 2026, the options remain limited. The Greek certificate authority HARICA provides domain validated certificates for onion addresses, and the process involves placing a file on your website so it can check that you control it. Despite years of requests, Let’s Encrypt still doesn’t offer free certificates for onion addresses. The Tor Project’s page on HTTPS for onion services covers the options.

One thing to note: public certificates are recorded in Certificate Transparency logs, which anyone can search. If you’d prefer your onion address to stay unpublished, don’t get a certificate for it.

Custom vanity addresses

You might have noticed that some onion addresses start with a recognisable word, such as the BBC’s or DuckDuckGo’s. These are known as vanity addresses, and they’re created with a program that produces millions of keys until it finds one whose address begins with the letters you’ve chosen.

A few characters take only seconds, whereas six or seven can take hours or days. Each additional character makes it dramatically harder. If you want to give it a try, the Tor Project has a brief guide to vanity addresses.

Two precautions. First, only generate keys on a computer you trust, since whoever runs the generator can see your secret key. Second, remember that a vanity prefix is not proof of identity, because fraudsters create lookalike addresses in exactly the same way. Always tell your visitors where to find your real, full address.

Common mistakes to avoid

The same few problems trip people up again and again.

Running an old version of Tor. Since September 2026, no version older than 0.4.9 works on the network. If your site suddenly fails to load, check this first.

Leaving the web server open to the internet. If Nginx listens on all addresses instead of 127.0.0.1, your website is also reachable on your public IP address, and the whole point is lost.

Losing the secret key. No backup means no address. There is no recovery procedure and no one to contact.

Pulling in outside resources. Every external font, script or image is a potential leak and a likely cause of broken pages for visitors who use the Safest security level.

Forgetting about moderation. Any feature that lets strangers post content makes you responsible for that content.

Publishing your address in the wrong places. Share your onion address through your own channels, such as your regular website, your social media profiles or a signed announcement, so that people can verify it really belongs to you.

Final thoughts

Hosting your own onion site is one of the most practical ways to understand how Tor works, and it’s a genuinely useful thing to offer people. Whether it’s a blog, a newsletter archive, a project page or a mirror of your current site, it can reach readers who would otherwise be blocked, tracked or censored.

The technical part is small: install a current version of Tor, set up a web server that only responds to requests on your own machine, add two lines to a configuration file and keep your key safe. The rest is simply the common sense that applies to any website: publish only what you’re permitted to publish, look after the people who visit, and keep your software up to date.

Do that, and you’ll end up with your own little corner of the onion web, built the right way.

Leave a Reply

Your email address will not be published. Required fields are marked *