A .onion site is reached through Tor, commonly with Tor Browser. Its network properties do not replace application authentication or prevent an app from exposing information through external services. This guide covers a persistent onion site; for temporary reviews, see Git branch previews over Tor.
What you get
- A v3 .onion address, the modern long-format hidden service
- Offshore hosting for a persistent onion service, subject to the service terms and applicable rules
- No KYC signup, no email required, and crypto payment
The steps
Get a server
Use Tor Hosting on a VM or Dedicated Tor Hosting on bare metal. Sign up with no KYC (a unique Account ID and recovery code if you prefer no email) and pay in crypto.
Put your service online
Choose the workflow your server actually uses. Tor Hosting with aaPanel uses Tor Manager and Onion Guard. Apps managed by the Impreza Agent use the platform deployment tools. Ordering the panel-based product does not mean it includes the same app lifecycle tools as an agent-managed deployment.
For aaPanel, follow the Community tutorial with screenshots. The Tor Hosting VM and Dedicated Tor Hosting pages describe the same panel tools on different infrastructure; do not assume their checkout options are identical.
For a supported app deployment, confirm the Impreza Agent is installed and online, deploy the app, and check that its web service works before adding Tor access.
Add the .onion hidden service
In the aaPanel workflow, use Tor Manager and follow the Community tutorial for Onion Guard configuration. In the Impreza Agent workflow, use the supported app’s Tor action and collect the resulting hostname. Check the operation’s result; an accepted request is not proof that the website is reachable.
Open the resulting address in Tor Browser and test the pages and sign-in your users need. An app with an onion address can still have public HTTP or other open ports. Review those routes separately if you intend to allow access only through Tor.
Keep it private
Serve assets from the same origin and avoid third-party fonts, analytics and CDNs that would leak metadata. Keep the content self-contained so nothing points back to the clearnet.
For a supported Impreza Agent deployment, your assistant can help publish and inspect the app through an authorized MCP connection. Confirm the deployment and available actions first. Do not apply the app workflow to an aaPanel service just because both offer onion hosting.
A hidden service hides the server, not a leaky app. Avoid clearnet redirects, external scripts and anything that phones home.
Maintain and recover the right environment
For apps managed by the Impreza Agent, use app inspection and review the app backup and restore guide for supported storage and recovery limits. These tools do not automatically cover an aaPanel website or every file on a server.
Preserving website data and preserving an onion address are separate recovery requirements. Confirm how the service’s onion identity is protected before a reinstall or move. App migration does not copy the onion identity; plan and test the destination address before directing users to it.
Temporary Git branch previews over Tor are a different workflow with compatibility requirements and expiry. They do not replace a persistent production onion site.
Start now
Pick Tor Hosting or an offshore VPS, and read the step by step in our docs.









