Build a persistent workspace, internal tool or customer application that approved Tor clients can reach. Impreza combines your server, app deployment and onion operations through the portal, REST API and MCP. You choose the app and capacity; client keys define who can discover its restricted onion service.
An address is only the starting point
A public onion address does not restrict visitors by itself. On an eligible Impreza Agent app, Tor client authorization requires an approved key before connecting. Keep application login and roles for the actions a user can perform after reaching the app.
This fits teams able to configure Tor clients and manage access credentials. A public customer website may be better served by an unrestricted onion endpoint. Short-lived Git reviews have a separate preview workflow; do not assume every preview inherits persistent-app controls.
Operate access from the same platform
Add named clients, inspect the authorization inventory and revoke individual keys. A compatible AI assistant can use MCP tools under your account permissions, while the portal and REST API provide other ways to perform supported operations.
Verify command completion and test with both authorized and unauthorized clients. Removing the final client makes the service public to Tor visitors again. Access changes restart the shared Tor daemon and may briefly interrupt other onion connections on that server.
Choose protection and keep control of identity
Eligible apps support standard, hardened and max protection profiles. Hardened adds stream limits; max requires a Tor build with proof-of-work support. These controls do not replace app authentication, secure code or a WAF, and are not a guarantee against every attack.
Encrypted identity export protects the keys behind your address. App backups protect different data. Keep both recovery plans, and account for one-time export retrieval and persistent address reservations. Rotation changes the public onion address; moving an existing identity requires a separate supported plan.
Match the server to the workload
Use a supported server with the Impreza Agent, version 0.6.19+ and the capabilities required by each operation. Existing servers need an explicit agent update; local MCP requires 0.41.0+. A nondefault profile at deployment also requires the initial-profile capability advertised by the agent.
Choose CPU, memory and storage for your app, database and Tor processes, then test representative traffic. Tor network conditions affect latency. This agent workflow is separate from aaPanel with Tor Manager and Onion Guard; selecting a Tor-branded plan alone does not establish compatibility with every feature described here.
Start with deployment with AI to choose a supported setup. Confirm agent eligibility before ordering or reconfiguring a server. Account ID signup is available without a personal email address; account and billing records can still exist.
Questions before you deploy
Is this anonymous hosting for every application?
Tor changes network access, not what your app records or what users disclose. Review external services, public routes, logs and application configuration. AI providers can receive prompts and tool results when you use an assistant.
Can I preserve my onion address during a move?
Identity export and import are separate from app-data restore. Existing address reservations require coordination with support before moving an already-used identity. Do not promise a seamless transfer or zero downtime.
Can I connect to Impreza itself over Tor?
Yes. Use the MCP over Tor guide for the portal, API, hosted MCP and documentation addresses. A compatible client must route its requests through Tor; publishing an onion app does not configure that connection automatically.
Where should I start?
Follow the client authorization guide, prepare identity recovery, and review requirements and exact operations before changing a live service.









