← All stories
● Covered by 1 source · 1 reportLow impact1 neutral

Guide to Self-Hosting a Website as a Tor Hidden Service

🔄 Updated 4d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Website now accessible via a .onion address.
  • Details Tor and Nginx configuration for hidden services.
  • Explains adapting static site generators for Tor.
  • Tor provides end-to-end encryption and anonymity.

Tor Hidden Service Setup

The site is now available as a hidden service on the Tor network, using a .onion address. This setup means there is no certificate authority, DNS, or exposed IP address. The .onion address is derived from a public key, and Tor provides end-to-end encryption for the connection.

Tor routes traffic through thousands of volunteer-run servers, ensuring anonymity for users. Hidden services extend this anonymity to the server itself, preventing any single party from linking user identity to online activity. The Tor Project, a nonprofit, develops this technology to promote human rights and freedom from tracking, surveillance, and censorship.

Configuring Tor for a Hidden Service

To set up a hidden service, users need to install Tor and configure it to point to a local port. This involves editing the /etc/tor/torrc file to specify a HiddenServiceDir and HiddenServicePort. The directory for the hidden service must be a dedicated, Tor-owned path, not the web root, as Tor stores the service's private key and hostname there.

After configuring, restarting the Tor service will generate the .onion address, which can be found in the hostname file within the specified HiddenServiceDir. For example, the generated address might look like "dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion".

Serving the Site with Nginx

Tor forwards traffic from port 80 of the .onion address to a local port, such as 127.0.0.1:8080. Therefore, the web server, like Nginx, needs to listen on this local port. An Nginx server block should be configured for the .onion address, without TLS, HTTP/2, or QUIC, as Tor handles the encryption and uses plain TCP.

The Nginx configuration specifies the listen address, server name (the .onion address), root directory for the site files, and index file. After reloading Nginx, the site becomes live on the Tor network.

Building for the Onion Address

For static sites, absolute links often embed the base URL. If a site is built for the clearnet, these links would redirect visitors back to the clearnet domain even when accessed via Tor. To prevent this, a separate build of the static site is required, using the .onion address as its base URL.

This can be achieved by running the static site generator (e.g., Hugo) with a specific baseURL parameter pointing to the .onion address. A deployment pipeline can automate this process, building the site once for the clearnet and once for Tor, and then synchronizing each version to its respective target.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

This article provides instructions on how to host a website as a Tor hidden service, making it accessible only within the Tor network. It details the configuration steps for Tor and Nginx, and explains how to adapt static site generation for a .onion address.