Short answer: OnionShare starts a web server on your computer and publishes it as a Tor onion. The other person opens that address in Tor Browser and downloads from you. There is no mailbox, Drive folder, or VPS. The file never leaves your disk until they fetch it. Anyone who has the address and the private key can fetch it too.
This is the send tab. The glossary card is OnionShare. Newsroom intake is a different tool: SecureDrop and press freedom.
What you actually do
- Download from onionshare.org — also shipped in Tails, Qubes, and documented on Whonix.
- Open a Share tab, drag the files, click Start sharing.
- OnionShare shows a v3
.onionand, by default, a private key (Tor client authentication). Copy both. - Send both on a channel you already trust — an encrypted chat, not a public post.
- The recipient pastes the address into Tor Browser, enters the key, and downloads.
- Keep your machine awake and online until they finish. Suspend the laptop and the onion disappears. Quit the app and it disappears.
By default the service stops after the first complete download. Uncheck that box only if several people should fetch the same bundle.
One-time versus saved
Closing a tab destroys that onion. Check “Always open this tab when OnionShare is started” before you start the server if you need the same address after a reboot (a long-lived dropbox or site). That stores a copy of the onion key on disk.
A public service (private key off) is for something you would put on a website. Leave the key on for a file that should stay between two people.
Other modes, same machine
Receive, website, and chat tabs are the same idea: your PC is the server. Receive is a lightweight dropbox — OnionShare’s own docs call it simpler and not as secure as SecureDrop. Chat needs Tor Browser at Standard or Safer (it uses JavaScript) and stores no history. None of these replace a newsroom’s air-gapped intake.
What this does not fix
- The address is a capability. If it leaks, whoever has it can hit the share while it is up. That is the threat the security design names.
- Attachments can still be hostile. OnionShare does not sandbox files. Do not open a received PDF in a host app while online: don’t open downloaded files while online.
- Metadata rides along. Strip it first: photo and PDF metadata.
- Email is still a third party if that is how you send the onion URL.
Sources
- OnionShare: How OnionShare works
- OnionShare: Security design
- OnionShare: Advanced — save tabs
- Tor Project: Sharing files with OnionShare
- OnionShare project: onionshare.org · GitHub
See also: don’t open downloaded files while online, photo and PDF metadata.