Tor provides strong encryption between the client and your hidden service, so SSL might seem redundant. However, HTTPS on .onion addresses provides several critical benefits. First, it authenticates your .onion address - a CA-signed certificate proves that the site visitors are connecting to is controlled by the entity that passed validation, preventing phishing attacks that use similar-looking .onion addresses.
Second, HTTPS enables browser features that are restricted to secure contexts. Service workers, the Web Crypto API, geolocation, camera access, and many other modern web APIs require HTTPS even on .onion domains. Without SSL, your Tor hidden service cannot use these capabilities, limiting the applications you can build.
Third, HTTPS provides defense-in-depth. If a vulnerability is discovered in Tor's encryption layer, your SSL certificate provides an independent layer of protection. Security best practice is to never rely on a single encryption mechanism when two complementary layers are available at minimal cost.