Hosting a Tor Onion Service (v3) on a VPS

A v3 onion needs no public IP, no DNS record and no open port. The setup path on a root KVM, and the operational limits worth knowing first.
Der Artikeltext ist auf Englisch. Header, Katalog und Kasse sind übersetzt.
What an onion service actually is
An onion service publishes a .onion address instead of a socket on the public internet. Clients build Tor circuits to reach it; the server's IPv4 never appears in DNS, never binds a public port, and never accumulates the reputation record that clearnet hosting creates. The application itself listens on localhost, and Tor tunnels requests in to it. Running middle relays or exits is a different workload with different exposure — that playbook lives with the relay documentation, not here.
VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.
Launch nowSetup path
- Provision a plain VPS in any location — geography is irrelevant to a .onion, so pick by your admin latency or by jurisdiction posture; one list price covers all twenty-one sites.
- Install Tor from the Tor Project repository, then declare a
HiddenServiceDirwithHiddenServicePort 80 127.0.0.1:8080in torrc. - Tor generates the v3 keypair and writes the hostname into the service directory. That string is your address — back the private key up, because there is no recovery.
- Bind the application to 127.0.0.1 only, and publish Onion-Location headers if a clearnet mirror exists.
Operational notes
- The v3 key is the address: lose it and the service is gone; leak it and anyone can clone the .onion byte for byte.
- Flood attacks find little to hit — with no public IP, volumetric DDoS has no target, which is a structural property, not a filtering product.
- The AUP applies to hidden services exactly as to clearnet ones: legal content, no CSAM, no phishing, no attacks. Onion does not change the policy layer.
Are onion services allowed on NulNet?
Yes. Tor hosting, onion services included, is an explicitly allowed workload; the AUP reads the same for a .onion as for a clearnet site, and no special permission or abuse deposit is required to run one.
Does the VPS need a special plan?
No. Any plan runs Tor — a small service fits Sentry at $7.50 list ($6.00 annual-eff). High-traffic onions outgrow RAM before CPU, so scale the memory line when circuits pile up.
Can a relay and an onion service share one machine?
Technically yes, but the roles age differently: relays collect abuse mail and bandwidth spikes, onions need quiet and stability. Separate machines keep one role's noise from contaminating the other.
Where should the onion backend live?
Anywhere you will administer honestly — the address hides the site from the network, not your SSH habits from the box. Harden sshd, tunnel the dashboard, and if the service ever needs exclusive CPU, the same checkout sells <a href="../dedicated/">dedicated servers</a> with IPMI.
Ready to launch?
Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.