Host with Server Manager on Windows, or headless Docker (ChatServer + Tor HS). Password rooms are server blind E2EE, so the host cannot derive the room key. Open rooms still encrypt in the browser, but the key is derived from the room ID, creating intentional public channels. Hidden rooms stay off the public list and use invite links. Add a password for private E2EE. Creators get Settings for closed joins, slow mode, lock later, and delete room, plus a Profile recovery code (My Rooms for hidden). Required message TTL, E2EE attachments, and optional Full Vanguards complete the stack.
Server Manager is the host-side control panel: it starts and stops ChatServer plus a Tor v3 Hidden Service, shows the .onion URL to share, optionally enables Full Vanguards, and lets you administer rooms and storage. The host never receives plaintext from clients; password-room keys stay in browsers. Open-room keys are derivable from the room id by design.
Start ChatServer first (Production, waits for /api/health), then enable Tor Copy and share the published .onion URL
Optional Full Vanguards checkbox (Python + Stem) for long-lived HS hardening
Live room list (room id, locked flag, online count only, no message content)
Remove a selected room in realtime: connected users are forced back to the lobby; ciphertext for that room is deleted with secure_delete + VACUUM
Remove SQL data: securely overwrites (then deletes) the SQLCipher DB, WAL/SHM, and db.key.dpapi; optional checkbox also wipes Tor Hidden Service keys (.onion identity)
Generate new address: securely wipes HS keys and publishes a new .onion (chat DB unchanged)
A startup from Finland.
Ciphertext storage
SQLCipher database under LocalAppData (Windows) or Docker volume. DPAPI / env key. Parameterized queries. Plaintext is never written to disk.
Close room to new members
blocks all joins (including invites); members stay
Slow mode
Send cooldown 1 min โฆ 4 h (applies to everyone, including creator)
Delete this room
Same wipe path as Server Manager room delete
Creator recovery code
Binds rooms you create; My rooms lists hidden; Copy / Restore
Rooms, invites & TTL
Open, password-protected, and/or hidden rooms with invite links and required per-message lifetime.
Server manager
Start ChatServer first (Production, waits for /api/health), then enable Tor Copy and share the published .onion URL Optional Full Vanguards checkbox (Python + Stem) for long-lived HS hardening Locks CORS to your onion: TORCHAT_ALLOWED_ONION on start + live POST /api/admin/cors-onion (no ChatServer restart) Live room list (room id, locked flag, online count only, no message content) Remove a selected room in realtime: connected users are forced back to the lobby; ciphertext for that room is deleted with secure_delete + VACUUM Remove SQL data: securely overwrites (then deletes) the SQLCipher DB, WAL/SHM, and db.key.dpapi; optional checkbox also wipes Tor Hidden Service keys (.onion identity) Generate new address: securely wipes HS keys and publishes a new .onion (chat DB unchanged) Point at your ChatServer project path and load/save host config as needed
Full Vanguards Guard-Discovery Protection
A standard Tor Hidden Service chooses its entry (guard) nodes randomly on every circuit build. Over time a network-level adversary can watch which relays the server connects to and gradually narrow down the real server IP. This is called a guard-discovery attack and is especially dangerous for long-lived hidden services.
Encryption
WebCrypto AES-256-GCM; PBKDF2-v2 domains at 600 000 iterations (torchat-join-v2 / torchat-e2ee-v2 locked = server-blind; torchat-open-v2 open = public key material). Envelopes: pbkdf2-v2 / ecdh-hybrid-v1
XSS hardening
No user innerHTML; messages and room ids via textContent / createElement
ECDH + safety number
1:1 hybrid ECDH; safety number from sorted SPKI pubs (3ร5 decimal); Mark verified / TOFU change warning (sessionStorage)
Promote OffCode Tor Chat E2EE. You can add any of these badges on your website.
C#, python , javascript
Self-hosted easy setup! Never been that easy
We have collected here some useful links to help you find out if OffCode Tor Chat E2EE is good.
Check the traffic stats of OffCode Tor Chat E2EE on SimilarWeb. The key metrics to look for are: monthly visits, average visit duration, pages per visit, and traffic by country. Moreoever, check the traffic sources. For example "Direct" traffic is a good sign.
Check the "Domain Rating" of OffCode Tor Chat E2EE on Ahrefs. The domain rating is a measure of the strength of a website's backlink profile on a scale from 0 to 100. It shows the strength of OffCode Tor Chat E2EE's backlink profile compared to the other websites. In most cases a domain rating of 60+ is considered good and 70+ is considered very good.
Check the "Domain Authority" of OffCode Tor Chat E2EE on MOZ. A website's domain authority (DA) is a search engine ranking score that predicts how well a website will rank on search engine result pages (SERPs). It is based on a 100-point logarithmic scale, with higher scores corresponding to a greater likelihood of ranking. This is another useful metric to check if a website is good.
The latest comments about OffCode Tor Chat E2EE on Reddit. This can help you find out how popualr the product is and what people think about it.
Do you know an article comparing OffCode Tor Chat E2EE to other products?
Suggest a link to a post with product alternatives.
Is OffCode Tor Chat E2EE good? This is an informative page that will help you find out. Moreover, you can review and discuss OffCode Tor Chat E2EE here. The primary details have been verified within the last quarter. So they could be considered up to date. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.