Tor v3 onion services support an authentication layer based on x25519 key pairs. The service operator generates a public/private key pair for each authorized client. The public key is placed in the hidden service's authorized_clients/ directory on the server, while the client adds the private key to their Tor configuration.
When a client attempts to connect, the Tor daemon on the server side checks if the client possesses a valid private key before establishing the connection. If the client does not have the key, the server does not respond - the service appears to not exist at all. This is significantly stronger than application-layer authentication because the filtering happens at the Tor protocol level.
Each authorized client gets their own unique key pair, allowing you to revoke access for individual clients by removing their public key file from the server. You can authorize up to 330 clients per hidden service using this mechanism.