ON
SOFTWARE

OnionShare

OnionShare is a privacy-focused tool for sharing files, hosting simple services and receiving messages through an onion-routed session. This page covers one-time transfers, access tokens, local folders and exposure limits.

Version 2.6.5Windows 64 位macOSLinuxGPL-3.0-or-later

What OnionShare provides

OnionShare can publish a temporary sharing session, receive files into a chosen folder, host a small static service or exchange messages through an onion-routed connection. It helps reduce direct exposure of a home address, but the shared files, session link and local endpoint still need careful handling.

Sessions and local exposure

Use a new session for a single task, choose a dedicated folder and share the access token only through a channel appropriate to the recipient. Close the session when the transfer is complete, inspect received files before opening them and avoid using a broad personal folder as the transfer root.

Maintenance note

This page reviews OnionShare for temporary file sharing, receiving, session tokens and local exposure boundaries. Content review date: 2026-08-23.

SAVE TO CLOUD

Save to your cloud drive

Open the cloud drive to get the file directly, or save it for convenient access on another device.

Links checked 2026-08-06
Save first, access when you need itOn desktop, scan with the matching cloud-drive app. On mobile, tap the save button.
GUIDE

OnionShare temporary transfer guide

Create a dedicated transfer folder, start one short session, send the access token privately and close the session after verifying the files.

Before you start

  • Prepare a dedicated folder containing only the files for this transfer.
  • Agree on a recipient and a separate channel for delivering the session token.
  • Decide how received files will be scanned, reviewed and retained.
01

Installation steps

  1. 01

    Install and select a folder

    Install OnionShare, open the intended mode and choose a narrow folder rather than a personal home directory or shared drive root.

  2. 02

    Start one temporary session

    Add a small set of files, start the session and copy the generated token without including it in a public post or shared project log.

  3. 03

    Verify and close

    Confirm that the recipient received the expected files, inspect the transfer folder and stop the session as soon as the task is complete.

02

Quick start

  1. 01

    Use clear file names

    Remove private identifiers from names when possible and keep a local manifest of what was intentionally shared.

  2. 02

    Review received files

    Save incoming files to a quarantine-like folder, scan them with the device security tools and open only what is expected.

  3. 03

    Rotate session habits

    Create a new session for each transfer, avoid reusing tokens and record the close time for sensitive exchanges.

Usage tips

  • A private transport does not make an unsafe file safe; review content, permissions and recipient identity separately.
  • Keep the application and relay configuration updated, and account for slower transfers over privacy networks.
  • Do not leave a session running after the intended recipient has finished.
Troubleshooting and uninstall

Why can the recipient not open the session?

Check that the session is still running, the token was copied exactly and both sides can reach the required network path. Create a fresh session rather than publishing the old token again.

Why are received files missing?

Check the selected destination, remaining storage and transfer log, then repeat with one small file before sending the full set.

  1. Close sessions and archive the manifestStop every active session, record what was shared and move received files to their reviewed destination.
  2. Remove local application dataUninstall OnionShare through the operating system and clear cached session data only after confirming that no required transfer remains.
FAQ

Frequently asked questions

Does OnionShare make a transfer permanently anonymous?

It provides a privacy-oriented transport, but files, tokens, device logs and recipient behavior can still reveal information. Use a dedicated folder and close each session.

Should a session token be reused?

Create a new session for each task and share the token privately. Reusing or publishing a token increases the chance of unintended access.

Does the download require an extraction code?

The Quark entry does not require one; the four-character code for the Baidu entry is shown beside its download entry.