Tor Bridge Hosting — Obfs4 on Your Own VPS

A bridge is Tor's unlisted front door: what it does that relays and exits do not, how to run obfs4 on a KVM, and what distribution costs. From $4.80/mo.
A bridge is Tor's unlisted front door: what it does that relays and exits do not, how to run obfs4 on a KVM, and what distribution costs. From $4.80/mo.
12 locations · 19 coins · SLA 99.95% · no KYC · public canary
The short answer
Short answer: a bridge is an unlisted Tor entry point — it moves clients into the network without appearing in the public directory, which is where relays and exits are published. Hosting one obfs4 bridge costs Core money ($4.80/mo annual-eff), roughly twenty minutes of setup, and one real decision: private or public distribution. Bridges are ordinary workloads here — Tor is welcome on every plan; relays and exits additionally go through a ticket so the abuse desk knows what the IP carries.
VPS from $4.80* — Core on the annual term (list $6/mo), one invoice for 12 months, no auto-charges. Dedicated with IPMI from $39.20/mo. Crypto invoice, no KYC.
Launch nowBridge, relay, exit — the actual differences
| Role | Listed? | Carries | Setup here |
|---|---|---|---|
| Bridge | no — handed out privately | clients' first hop into Tor | obfs4 on any KVM, no ticket |
| Middle relay | yes — public directory | transit between Tor hops | ticket; stable IP recommended |
| Exit | yes — IP publicly flagged | traffic to the open internet | by ticket; reduced exit policy; abuse mailbox you read |
The tier follows from the role. A bridge hides the fact that it is Tor at all; a middle relay strengthens the network publicly without touching the censorship-sensitive end; an exit puts your rack IP on every destination site's logs and needs the operational maturity of a read abuse inbox. The exit-relay page covers that end; the Iceland relay setup and the Netherlands relay setup show the rack-side details.
Running obfs4, step by step
The whole run fits one SSH session on Debian 12:
- Order a KVM with Debian 12. Core — 2 vCPU / 4 GB DDR5 / 80 GB NVMe — carries a private bridge with headroom; Amsterdam or Frankfurt for EU latency, Reykjavik when jurisdiction is the reason.
- Install from the Debian repositories:
apt install tor obfs4proxy. No third-party scripts or packages are required. - In torrc set
BridgeRelay 1andServerTransportPlugin obfs4 exec /usr/bin/obfs4proxy, let ORPort auto-assign, and restart tor — the bridge line lands in the log. - Allow the ORPort and the obfs4 listen port in the firewall, then copy the full
obfs4line — cert and iat-mode included — from/var/log/tor/log. - Hand the line to the people who need it. Public distribution invites scanning and faster blocking; private sharing survives longer.
What it costs and where it hurts
Core at $4.80/mo annual-eff is the entire bill; a private bridge sits orders of magnitude below the 1 Gbps unmetered port, so bandwidth is never the topic. The honest cost is distribution. A publicly submitted bridge gets enumerated and blocked by censors faster than a private one; a private bridge makes you the distribution channel — lose the bridge line and you have lost the entry. For censored users without a server at all, Snowflake covers the bootstrapping case instead.
Two rack notes: the bridge's MetricsPort statistics stay on your disk under your control, and the published privacy posture applies as everywhere — no traffic logs (connection metadata ages out inside 24 h). If the account should not touch a mailbox at all, token signup handles it; the anonymous VPS guide covers the account layer.
Host an obfs4 bridge — Core from $4.80/mo annual-eff.
Deploy a bridgeIs hosting a Tor bridge allowed on VPSbit?
Yes. Bridges are ordinary workloads on every plan; relays and exits additionally go through a support ticket so the abuse desk knows what the IP carries.
How much bandwidth does a bridge use?
Light relative to the port: a private bridge sits far below the 1 Gbps unmetered ceiling, and Core's 2 vCPU is a bigger constraint than traffic will ever be.
Bridge or relay — which should I run?
A bridge helps censored users enter quietly; a middle relay strengthens the network publicly. Exits need a ticket, a reduced policy and an abuse mailbox you actually read.
Does the bridge need a dedicated IP?
Not required. A dedicated IPv4 ($3.50/mo) keeps the endpoint stable across rebuilds, but the obfs4 key material rotates on redeploy regardless, so the line changes either way.
Do you log bridge users?
The published policy on every rack is no traffic logs (connection metadata ages out inside 24 h); the bridge's own MetricsPort numbers live on your disk, under your control.
Primary sources
Ready to launch?
Build the box — VPS or bare metal — create the password, pay the invoice that follows.