Tor (.onion)
The API, landing page, registration and account flows, partner dashboard, staff console, and this
documentation site are mirrored on Tor v3 onion services, including the interactive API reference
at /docs/ui. You can register, activate an account, sign in, manage a team, quote, open a deposit
channel and follow a swap to completion without your network IP address reaching the application.
This documentation site is on Tor too. It is a separate origin from the API, so it has its own onion service and its own address:
chainflip45pvbqr3insxwjq7634bbk624pgm66mgpqxzylcws47ceyd.onion
Prefer it over docs.chainflip-broker.io. Reading the docs over clearnet while calling the API over
Tor still tells us, and anyone watching, that someone at your address is reading our integration
guide - the onion address above closes that gap.
What this gives you, exactly
You can reach our API without revealing your IP address to us or to anyone watching the connection. The swap itself is a public on-chain transaction, exactly as it is over clearnet.
That is the whole claim, and it is worth being precise about both halves.
What changes. Over clearnet every request produces a log entry carrying the caller's IP address
alongside the URL, the API key in it and the user agent. Our ingress preserves the real client
address deliberately and the application records it. Over the onion there is no caller address to
record - every request reaches us from the Tor daemon, identical for every caller - so the log
entry carries the literal string onion where an address would otherwise be.
What does not change. The deposit address, the amounts, the timing and the destination are all on-chain and permanently public. Chainflip is a public protocol and a swap made over the onion looks exactly like a swap made over clearnet.
We do not offer, and will not claim, private, anonymous or untraceable swaps. A .onion endpoint
hides the API caller. It does not hide the swap.
Addresses
| Environment | Surface | Address |
|---|---|---|
| Production | API + landing page | chainflip37gkyf3nkgufkolp2grpbchoysvro57wz3d3kurhhyj4zad.onion |
| Production | Documentation | chainflip45pvbqr3insxwjq7634bbk624pgm66mgpqxzylcws47ceyd.onion |
| Testing | API + landing page | broker37cyuuvorore4mbcexbc6pw47n6xdx65upkrecq3eumqgtmnad.onion |
| Testing | Documentation | broker45ckafaqt342nxdim45mwtmxqwfvhjtkj4zyihlnvjqyeeeoqd.onion |
These are v3 onion services, so each address is that service's public key - there is no certificate to check and nothing to trust on our word.
⛔ Four separate identities with four separate keys. A chainflip… address is always production and
a broker… address is always testing; a testnet address is never a stand-in for the mainnet one, or
the other way round.
Using it
Point any Tor-capable client at the onion address. The API is identical - same paths, same parameters, same API key, same responses.
# Note --socks5-hostname, not --socks5: the .onion name must be resolved by Tor, not by your
# machine's resolver.
curl --socks5-hostname 127.0.0.1:9050 \
"http://chainflip37gkyf3nkgufkolp2grpbchoysvro57wz3d3kurhhyj4zad.onion/quotes?apiKey=YOUR_KEY&sourceAsset=btc.btc&destinationAsset=eth.eth&amount=0.1"
Tor Browser works without any configuration. If you visit the clearnet site in Tor Browser, it will
offer you the onion version automatically: we send an Onion-Location header.
What is available
| Feature | Status |
|---|---|
| Quotes, swaps, status, fees, feed, transaction payloads, RPC | ✅ Same as clearnet |
| Assets and networks | ✅ Same as clearnet |
MCP endpoint (/mcp), full tool surface | ✅ Same as clearnet, including swap execution |
API documentation (/docs) | ✅ Same as clearnet |
Health (/health) | ✅ Same as clearnet |
| Registration, sign-in, password recovery, invitations, first-login setup | ✅ Available |
| Partner dashboard and team management | ✅ Available with the same account authorization |
The whole product surface is available on the onion: you can obtain an API key, activate and manage
an account, use the staff console, quote, open a deposit channel and follow a swap without first
visiting chainflip-broker.io.
A signed-in session still identifies your account, and the swap is still public on-chain. Tor hides where you connect from, not who you are once you log in.
Attribution and API keys
The REST API works exactly as it does on clearnet: /quotes, /swap, /status-*, /fees and
/feed need your API key and return 401 without it. Your key is what identifies your integration
for commission, over either transport.
The MCP endpoint accepts calls without a key, over the onion just as over clearnet. Those book as
house volume with no partner commission. Pass your apiKey if you want the volume attributed to
you.
Things worth knowing
- It is slower. Tor adds seconds and is variable. Nothing on our side expires a quote, so a slow round trip costs you accuracy against a moving market rather than a failed request.
- No TLS, and that is correct. Onion services are self-authenticating: the address is the
public key.
http://over an onion service is end-to-end encrypted by Tor itself. - One daemon. The onion is served by a single Tor instance today. If it is down, clearnet is unaffected.