The first step is telling Tor to create a hidden service and forward connections to Nginx. Edit your /etc/tor/torrc file to define the hidden service directory and the port mapping:
# /etc/tor/torrc
HiddenServiceDir /var/lib/tor/my_hidden_service/
HiddenServicePort 80 127.0.0.1:8080
HiddenServiceVersion 3This configuration tells Tor to listen on virtual port 80 and forward traffic to localhost port 8080, where Nginx will be listening. After saving, restart Tor with systemctl restart tor and your .onion address will be generated in /var/lib/tor/my_hidden_service/hostname.
For production deployments, consider adding HiddenServiceSingleHopMode and HiddenServiceNonAnonymousMode only if your server identity is already public and you want reduced latency. For most privacy-focused use cases, keep the default 3-hop circuits.