OnionShare
OnionShare is a privacy-focused tool for sharing files, hosting simple services and receiving messages through an onion-routed session. This page covers one-time transfers, access tokens, local folders and exposure limits.
What OnionShare provides
OnionShare can publish a temporary sharing session, receive files into a chosen folder, host a small static service or exchange messages through an onion-routed connection. It helps reduce direct exposure of a home address, but the shared files, session link and local endpoint still need careful handling.
Sessions and local exposure
Use a new session for a single task, choose a dedicated folder and share the access token only through a channel appropriate to the recipient. Close the session when the transfer is complete, inspect received files before opening them and avoid using a broad personal folder as the transfer root.
Maintenance note
This page reviews OnionShare for temporary file sharing, receiving, session tokens and local exposure boundaries. Content review date: 2026-08-23.
Save to your cloud drive
Open the cloud drive to get the file directly, or save it for convenient access on another device.
Quark Cloud Drive
RecommendedSave OnionShare to this cloud drive
Baidu Netdisk
Save OnionShare to this cloud drive
OnionShare temporary transfer guide
Create a dedicated transfer folder, start one short session, send the access token privately and close the session after verifying the files.
Before you start
- Prepare a dedicated folder containing only the files for this transfer.
- Agree on a recipient and a separate channel for delivering the session token.
- Decide how received files will be scanned, reviewed and retained.
Installation steps
- 01
Install and select a folder
Install OnionShare, open the intended mode and choose a narrow folder rather than a personal home directory or shared drive root.
- 02
Start one temporary session
Add a small set of files, start the session and copy the generated token without including it in a public post or shared project log.
- 03
Verify and close
Confirm that the recipient received the expected files, inspect the transfer folder and stop the session as soon as the task is complete.
Quick start
- 01
Use clear file names
Remove private identifiers from names when possible and keep a local manifest of what was intentionally shared.
- 02
Review received files
Save incoming files to a quarantine-like folder, scan them with the device security tools and open only what is expected.
- 03
Rotate session habits
Create a new session for each transfer, avoid reusing tokens and record the close time for sensitive exchanges.
Usage tips
- A private transport does not make an unsafe file safe; review content, permissions and recipient identity separately.
- Keep the application and relay configuration updated, and account for slower transfers over privacy networks.
- Do not leave a session running after the intended recipient has finished.
Troubleshooting and uninstall
Why can the recipient not open the session?
Check that the session is still running, the token was copied exactly and both sides can reach the required network path. Create a fresh session rather than publishing the old token again.
Why are received files missing?
Check the selected destination, remaining storage and transfer log, then repeat with one small file before sending the full set.
- Close sessions and archive the manifestStop every active session, record what was shared and move received files to their reviewed destination.
- Remove local application dataUninstall OnionShare through the operating system and clear cached session data only after confirming that no required transfer remains.
Frequently asked questions
Does OnionShare make a transfer permanently anonymous?
It provides a privacy-oriented transport, but files, tokens, device logs and recipient behavior can still reveal information. Use a dedicated folder and close each session.
Should a session token be reused?
Create a new session for each task and share the token privately. Reusing or publishing a token increases the chance of unintended access.
Does the download require an extraction code?
The Quark entry does not require one; the four-character code for the Baidu entry is shown beside its download entry.