Launch pricing: every plan costs 30% less than the cheapest offshore competitor we track. See the benchmarkEvery plan 30% under the cheapest offshore host

Knowledge base · VPS

How to run a Tor relay, bridge or onion service on a VPS

Run a Tor relay on a VPS: install tor from the Tor Project's repository, then set up a middle relay, an obfs4 bridge, an exit relay or an onion service.

Updated 11 min read

In this guide

  • Install tor from the Tor Project's own repository, which carries the current stable release.
  • A middle or guard relay needs a nickname, a public contact, an open ORPort and ExitRelay 0.
  • A bridge adds the obfs4 transport and stays out of the public relay list.
  • An exit needs a tor-exit reverse DNS name, a reduced exit policy, a notice page and a local DNS resolver, and it draws abuse reports.
  • An onion service points a .onion address at a site on 127.0.0.1; back up its key.
VPS9 sections
All guides
On this page
  1. Before you run a Tor relay on a VPS: pick a role
  2. Install Tor from the Tor Project's repository
  3. Run a middle or guard Tor relay on your VPS
  4. Run a Tor bridge on a VPS
  5. Run a Tor exit relay responsibly
  6. Host a Tor onion service (hidden service)
  7. Keep your Tor relay healthy
  8. Troubleshooting
  9. Frequently asked questions

To run a Tor relay on a VPS, install tor from the Tor Project's own repository, write a nickname, a contact and an ORPort into /etc/tor/torrc, open that port in the firewall and restart tor. The same tor also runs a bridge with the obfs4 transport, an exit relay, or an onion service for your own site.

The steps use an Offshore VPS on Debian 12 or 13 or Ubuntu 22.04 or 24.04 LTS, with root access as in getting started. Give each server one role: the Tor Project advises against hosting an onion service on a relay, and a bridge should not reuse a public relay's address.

Before you run a Tor relay on a VPS: pick a role

RoleWhat it doesAbuse reportsTor Project minimumPlan to start with
Middle or guard relayRelays encrypted traffic; can later serve as a guard, the first hopUsually none10 Mbit/s each way, 100 GB a month, 512 MB RAM (1 GB above 40 Mbit/s)Sloop: 2 GB RAM, $3.49 a month
BridgeUnlisted entry point for users on censored networksUnlikely1 Mbit/s each wayDinghy: 1 GB, $2.39
Exit relayThe last hop: destinations see your server's IP addressExpect them1.5 GB RAM recommendedCutter: 4 GB, $5.49
Onion serviceYour site at a .onion address, reachable only over TorOnly about your contentWhat your site needsDinghy for a small site

Every VPS plan includes the dedicated IPv4 address a relay needs, and traffic is unmetered under fair use on our 1 Gbps ports. If a busy relay causes a problem on a VPS, we tell you in the client area and suggest a fix first. Cap tor as shown below, or move a fast relay to a dedicated server, which you can use to its stated capacity.

Our acceptable use policy welcomes relays and bridges and allows exits that follow the Tor Project's guidance. Relay addresses and contact lines are public: if the relay must not lead back to you, read how to buy a VPS anonymously. The location decides which country's law applies, and the network page compares latency.

Install Tor from the Tor Project's repository

The Tor Project recommends its own repository over Debian's LTS version and Ubuntu's universe packages, which "have not reliably been updated". It carries the current stable series, 0.4.9:

apt update
apt install -y apt-transport-https gnupg wget
wget -qO- https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --dearmor | tee /usr/share/keyrings/deb.torproject.org-keyring.gpg >/dev/null
. /etc/os-release
cat > /etc/apt/sources.list.d/tor.sources <<EOF
Types: deb deb-src
URIs: https://deb.torproject.org/torproject.org/
Suites: $VERSION_CODENAME
Components: main
Signed-By: /usr/share/keyrings/deb.torproject.org-keyring.gpg
EOF
apt update
apt install -y tor deb.torproject.org-keyring
tor --version

/etc/os-release supplies your codename, such as trixie or noble. The keyring package keeps the signing key current, and the last command should print a 0.4.9 version.

Run a middle or guard Tor relay on your VPS

Replace the contents of /etc/tor/torrc with these lines from the Tor Project's relay guide, using your own values:

Nickname    myNiceRelay
ContactInfo YOUR_CONTACT_ADDRESS
ORPort      443
ExitRelay   0
SocksPort   0
Nickname
1 to 19 letters and digits.
ContactInfo
How others reach you if the relay misbehaves. It is published, so use an address made for it; it is required if you run several relays.
ORPort
The port that clients and relays connect to, on IPv4 and IPv6. Any free port works.
ExitRelay 0
Traffic stays inside the Tor network.
SocksPort 0
Closes the local client port 9050 that the package opens by default.

Open the port, restart tor and read the log. If UFW is not active yet, allow SSH first, as in the hardening guide.

ufw allow 443/tcp
systemctl restart tor@default
journalctl -e -u tor@default

The reachability check can take up to 20 minutes and ends with Self-testing indicates your ORPort ... is reachable from the outside. Excellent. Publishing server descriptor. About three hours later, find the relay on Relay Search by the fingerprint in /var/lib/tor/fingerprint. Traffic then ramps up over weeks, as the Tor Project's lifecycle of a new relay explains.

Limit the bandwidth (optional)

To cap a relay, add one of these blocks to torrc and restart tor:

# average and burst rate, in each direction
RelayBandwidthRate  25 MBytes
RelayBandwidthBurst 50 MBytes

# or a monthly quota
AccountingStart month 1 00:00
AccountingMax   4 TBytes

Tor counts in powers of two, so 25 MBytes a second is about 210 Mbit/s. At the quota, tor hibernates until the next period, which the tor manual prefers to a very low rate.

Run a Tor bridge on a VPS

A bridge is a relay missing from the public directory, so it is harder to block. Users reach it through obfs4, a pluggable transport that transforms Tor traffic to get past censorship. As in the Tor Project's bridge guide, install it and replace torrc:

apt install -y obfs4proxy
BridgeRelay 1
ORPort 8443
ServerTransportPlugin obfs4 exec /usr/bin/obfs4proxy
ServerTransportListenAddr obfs4 0.0.0.0:8080
ExtORPort auto
ContactInfo YOUR_CONTACT_ADDRESS
Nickname PickANickname

Use two different free ports above 1024 and avoid 9001, which censors may scan for; lower ports need two extra steps from the guide. Open both and restart:

ufw allow 8443/tcp
ufw allow 8080/tcp
systemctl restart tor@default

The log should show Registered server transport 'obfs4'; if it does not, check the ServerTransportPlugin path. The Tor Project now develops obfs4proxy as lyrebird, a fork with more transports, but Debian 12 and 13 and Ubuntu 22.04 and 24.04 still package obfs4proxy. Where lyrebird is packaged instead, install it and use /usr/bin/lyrebird.

Your bridge line is in /var/lib/tor/pt_state/obfs4_bridgeline.txt: add the IPv4 address, the obfs4 port and the fingerprint from /var/lib/tor/fingerprint to get Bridge obfs4 SERVER_IP:8080 FINGERPRINT cert=... iat-mode=0. The Tor Project distributes the bridge unless you set BridgeDistribution none, and users can take days or weeks to arrive. Keep bridges out of relay families, and do not convert an existing relay.

Run a Tor exit relay responsibly

Destinations see an exit's IP address as the source of its traffic, so exits draw abuse complaints and, the Tor Project says, "have the greatest legal exposure and liability of all the relays". Our acceptable use policy allows them if you follow the Tor Project's exit guidance with a reduced exit policy. As the EFF advises, give the exit its own IP address, keep no personal data on it and never route your own traffic through it.

1. Request a reverse DNS name

Before you enable exiting, choose Set the reverse DNS (PTR) under Server actions on your server's page in the client area, with a hostname on a domain you own, such as tor-exit.example.org. The Tor Project suggests "tor-exit" in the name, never torproject.org.

2. Prepare the exit notice

A page on port 80 tells anyone who checks the address that it is a Tor exit; its authors say this "has proven very effective at reducing abuse complaints". Copy the template that comes with tor:

cp /usr/share/doc/tor/tor-exit-notice.html /etc/tor/tor-exit-notice.html

Minimized Ubuntu images leave out documentation files. If the file is missing, extract it from the package instead:

cd /tmp && apt download tor
dpkg-deb --fsys-tarfile tor_*.deb | tar -xO ./usr/share/doc/tor/tor-exit-notice.html > /etc/tor/tor-exit-notice.html

Then edit the parts marked FIXME: your hostname, a contact address, and the US-only section, which non-US operators remove.

3. Configure the exit

Nickname    myExitRelay
ContactInfo YOUR_CONTACT_ADDRESS
ORPort      443
DirPort     80
DirPortFrontPage /etc/tor/tor-exit-notice.html
ExitRelay   1
ReducedExitPolicy 1
SocksPort   0

The reduced policy accepts about 65 ports, among them the web, secure mail and SSH, but not port 25, which our network also closes by default. ExitPolicy lines apply first, so ExitPolicy reject *:22 would drop SSH too; IPv6Exit 1 adds IPv6. The DirPort still serves the notice, though relays no longer publish it.

4. Run a local DNS resolver and start

Exits resolve names for Tor users, so the Tor Project asks for a local caching, DNSSEC-validating resolver; its Debian and Ubuntu steps use Unbound. Our added rm matters on Ubuntu, where /etc/resolv.conf is a systemd-resolved link: systemd-resolved only reads a plain file put in its place, as its manual describes.

apt install -y unbound
systemctl enable --now unbound
cp /etc/resolv.conf /etc/resolv.conf.backup
rm -f /etc/resolv.conf
echo nameserver 127.0.0.1 > /etc/resolv.conf
chattr +i /etc/resolv.conf
ufw allow 443/tcp
ufw allow 80/tcp
systemctl restart tor@default

Unbound answers on localhost only by default; keep it that way, since an open resolver breaks our acceptable use policy. Then http://SERVER_IP/ should show the notice.

How we handle complaints about your exit

Reports about traffic that Tor users send through your exit go through our normal complaints process, not an automatic suspension. Each is checked against the law where the server runs; foreign notices, including US DMCA notices, are answered, not enforced, and we can pass the substance on in your client area. On a dedicated or GPU server, tell us by ticket before you start the exit, so we can route reports to you quickly.

Host a Tor onion service (hidden service)

An onion service, or Tor hidden service as tor's settings call it, publishes a site at a .onion address that works only through Tor. It needs no open ports, because tor only connects outward, so the site listens on 127.0.0.1 alone. Install nginx, remove its default site, which answers on every address, and serve your pages locally:

apt install -y nginx
rm /etc/nginx/sites-enabled/default
mkdir -p /var/www/onion
echo 'Hello from my onion site' > /var/www/onion/index.html
cat > /etc/nginx/conf.d/onion.conf <<'EOF'
server {
    listen 127.0.0.1:8080;
    root /var/www/onion;
    server_tokens off;
}
EOF
nginx -t
systemctl reload nginx

Add two lines to torrc from the Tor Project's onion service guide, restart tor and read your address:

HiddenServiceDir /var/lib/tor/my-website/
HiddenServicePort 80 127.0.0.1:8080
systemctl restart tor@default
cat /var/lib/tor/my-website/hostname

Open it in Tor Browser. Keep the directory under /var/lib/tor, where the tor service may write. Its hs_ed25519_secret_key file is your address, since the .onion name is its public key: whoever copies it can impersonate the service, and losing it loses the address, so back it up as shown below.

Do not leak the server's address

  • Keep ports 80 and 443 closed, so the pages cannot be found on the server's public IP.
  • Hide version banners, error details, status pages and debug output such as PHP's phpinfo(), which can reveal the server's real name and address.
  • Mind outgoing connections, such as DNS lookups, mail or fetching URLs for visitors: they come from your real IP, as Riseup's onion service guide explains. The Tor Project's operational security page covers the rest.

Announce it from a public site (optional)

If the site also runs publicly over HTTPS, this line in its HTTPS server block lets Tor Browser offer the onion address, as the Onion-Location guide shows. It links the two addresses: fine for a public mirror, wrong for an anonymous service.

add_header Onion-Location http://YOUR_ONION_ADDRESS.onion$request_uri;

Keep your Tor relay healthy

Automatic updates

Let the unattended-upgrades from the hardening guide update tor too. Per the Tor Project's update guide, add the first line inside the Unattended-Upgrade::Origins-Pattern block of /etc/apt/apt.conf.d/50unattended-upgrades on Debian, or the second inside Unattended-Upgrade::Allowed-Origins on Ubuntu, then test with unattended-upgrade --debug --dry-run.

"origin=TorProject";
"TorProject:${distro_codename}";

Backups

/var/lib/tor holds the relay's identity keys, a bridge's pt_state and your onion service's key; without them, a reinstalled server starts as a new relay. Archive it, as the Tor Project suggests, and keep the file encrypted off the server. To restore, stop tor and run tar -xzf tor-backup.tar.gz -C /var/lib as root, which keeps owners and permissions.

tar -czf /root/tor-backup.tar.gz -C /var/lib tor

Monitoring with nyx

nyx, the Tor Project's terminal monitor, shows bandwidth, connections and events live. The tor package already opens the control socket it uses, so run it as root:

apt install -y nyx
nyx

Several relays: set a family

Declare your relays a family, so that clients never use two of them in one circuit. Since tor 0.4.9 a family shares a secret key, as the Tor Project's FamilyId guide describes; its post-install guide calls the older MyFamily list removed. Run the first command once, on one relay: it writes myrelays.secret_family_key and prints a FamilyId line, and running it again overwrites the key. On every relay, install the key, add that line to torrc and reload. Keep the key secret.

tor --keygen-family myrelays
install -o debian-tor -g debian-tor -m 600 myrelays.secret_family_key /var/lib/tor/keys/
systemctl reload tor@default

Troubleshooting

tor does not start

Check the configuration the way the service does before each start. It prints what it rejects, such as a mistyped option, an invalid nickname or a port already in use, which ss -tlnp shows:

tor --defaults-torrc /usr/share/tor/tor-service-defaults-torrc -f /etc/tor/torrc --verify-config

The ORPort is not reachable

Your server has not managed to confirm reachability for its ORPort(s) means the port is blocked from outside, and the relay publishes nothing until it is reachable. Compare ufw status with the ORPort line. If only the IPv6 address fails, fix IPv6 or use ORPort 443 IPv4Only.

Frequently asked questions

Can I run a Tor relay on a VPS?

Yes. A relay needs an IPv4 address, a reachable TCP port and, for a middle or guard relay, at least 10 Mbit/s each way. Every Offshore VPS is a KVM machine with full root and a dedicated IPv4 address, and our acceptable use policy allows relays, bridges and exits.

It depends on the country, both yours and the server's. For the United States, the EFF's legal FAQ for relay operators knows of no one sued, prosecuted or convicted for running a relay, and believes relays, exits included, are legal under US law. Exits carry the most legal exposure.

Will I get abuse complaints for a Tor relay?

Rarely for a middle, guard or bridge relay: the Tor Project says guard and middle relays usually get none, and bridges are unlikely to. Exits do, because destinations see their IP address. We handle those reports under our complaints process, not by automatic suspension.

How much bandwidth does a Tor relay need?

The Tor Project's relay requirements ask for at least 10 Mbit/s each way for a middle or guard relay, 16 recommended, and 100 GB of traffic a month, ideally 2 TB. A bridge needs 1 Mbit/s. Our 1 Gbps ports are unmetered under fair use.

Can I run an onion service and a normal site on the same VPS?

Yes: one web server can serve the public site on the server's IP address and the onion site on 127.0.0.1, as long as neither answers for the other's host name. An Onion-Location header then points Tor Browser users to the onion address. That links the two, so an anonymous service needs its own server.

Stuck on a step?

Dedicated and GPU customers can open a ticket from the client area with the server’s IP address and what they tried. First reply target: under 12 hours. For every other server, use the Server actions on its page, the guides and the network status page.

Welcome back

Sign in to manage your servers and your balance.

No KYCHuman check by Cloudflare TurnstileNo tracking