All systems operational 12 elite locations · Europe & Asia Pay with crypto · 0 KYC
Home / Guides / Tor Bridge Hosting — Obfs4 on Your Own VPS
How-to

Tor Bridge Hosting — Obfs4 on Your Own VPS

Tor bridge hosting guide - obfs4 bridge on your own VPS

A bridge is Tor's unlisted front door: what it does that relays and exits do not, how to run obfs4 on a KVM, and what distribution costs. From $4.80/mo.

Short answer

A bridge is Tor's unlisted front door: what it does that relays and exits do not, how to run obfs4 on a KVM, and what distribution costs. From $4.80/mo.

12 locations · 19 coins · SLA 99.95% · no KYC · public canary

The short answer

Short answer: a bridge is an unlisted Tor entry point — it moves clients into the network without appearing in the public directory, which is where relays and exits are published. Hosting one obfs4 bridge costs Core money ($4.80/mo annual-eff), roughly twenty minutes of setup, and one real decision: private or public distribution. Bridges are ordinary workloads here — Tor is welcome on every plan; relays and exits additionally go through a ticket so the abuse desk knows what the IP carries.

VPS from $4.80* — Core on the annual term (list $6/mo), one invoice for 12 months, no auto-charges. Dedicated with IPMI from $39.20/mo. Crypto invoice, no KYC.

Launch now

Bridge, relay, exit — the actual differences

RoleListed?CarriesSetup here
Bridgeno — handed out privatelyclients' first hop into Torobfs4 on any KVM, no ticket
Middle relayyes — public directorytransit between Tor hopsticket; stable IP recommended
Exityes — IP publicly flaggedtraffic to the open internetby ticket; reduced exit policy; abuse mailbox you read

The tier follows from the role. A bridge hides the fact that it is Tor at all; a middle relay strengthens the network publicly without touching the censorship-sensitive end; an exit puts your rack IP on every destination site's logs and needs the operational maturity of a read abuse inbox. The exit-relay page covers that end; the Iceland relay setup and the Netherlands relay setup show the rack-side details.

Running obfs4, step by step

The whole run fits one SSH session on Debian 12:

  1. Order a KVM with Debian 12. Core — 2 vCPU / 4 GB DDR5 / 80 GB NVMe — carries a private bridge with headroom; Amsterdam or Frankfurt for EU latency, Reykjavik when jurisdiction is the reason.
  2. Install from the Debian repositories: apt install tor obfs4proxy. No third-party scripts or packages are required.
  3. In torrc set BridgeRelay 1 and ServerTransportPlugin obfs4 exec /usr/bin/obfs4proxy, let ORPort auto-assign, and restart tor — the bridge line lands in the log.
  4. Allow the ORPort and the obfs4 listen port in the firewall, then copy the full obfs4 line — cert and iat-mode included — from /var/log/tor/log.
  5. Hand the line to the people who need it. Public distribution invites scanning and faster blocking; private sharing survives longer.

What it costs and where it hurts

Core at $4.80/mo annual-eff is the entire bill; a private bridge sits orders of magnitude below the 1 Gbps unmetered port, so bandwidth is never the topic. The honest cost is distribution. A publicly submitted bridge gets enumerated and blocked by censors faster than a private one; a private bridge makes you the distribution channel — lose the bridge line and you have lost the entry. For censored users without a server at all, Snowflake covers the bootstrapping case instead.

Two rack notes: the bridge's MetricsPort statistics stay on your disk under your control, and the published privacy posture applies as everywhere — no traffic logs (connection metadata ages out inside 24 h). If the account should not touch a mailbox at all, token signup handles it; the anonymous VPS guide covers the account layer.

Host an obfs4 bridge — Core from $4.80/mo annual-eff.

Deploy a bridge
Is hosting a Tor bridge allowed on VPSbit?

Yes. Bridges are ordinary workloads on every plan; relays and exits additionally go through a support ticket so the abuse desk knows what the IP carries.

How much bandwidth does a bridge use?

Light relative to the port: a private bridge sits far below the 1 Gbps unmetered ceiling, and Core's 2 vCPU is a bigger constraint than traffic will ever be.

Bridge or relay — which should I run?

A bridge helps censored users enter quietly; a middle relay strengthens the network publicly. Exits need a ticket, a reduced policy and an abuse mailbox you actually read.

Does the bridge need a dedicated IP?

Not required. A dedicated IPv4 ($3.50/mo) keeps the endpoint stable across rebuilds, but the obfs4 key material rotates on redeploy regardless, so the line changes either way.

Do you log bridge users?

The published policy on every rack is no traffic logs (connection metadata ages out inside 24 h); the bridge's own MetricsPort numbers live on your disk, under your control.

Primary sources

Ready to launch?

Build the box — VPS or bare metal — create the password, pay the invoice that follows.