# The Documentation For Anyone

Anyone is a decentralized communication network built on anonymity, privacy, and global accessibility. Run a relay, develop with our SDK, or simply connect through the network with available tools.

## How to Use the Docs

These docs are the comprehensive overview of how to *use* the Anyone Protocol. It includes guides for operating a relay, connecting to the network, building apps on top of the network and configuring your hardware!&#x20;

## Who are these Docs for

<table><thead><tr><th width="276.4000244140625">You are ...</th><th width="174.7999267578125">Start with ...</th></tr></thead><tbody><tr><td>Running a relay</td><td><a href="/pages/AWPTxAeEmwViLBHULgmP">Relay Operators</a></td></tr><tr><td>Using the Anyone Router</td><td><a href="/pages/k6E28mCFmvQDwrhPAGBy">Hardware Users</a></td></tr><tr><td>Building with the SDK</td><td><a href="/pages/S7NzyHn6PWAJw42sH8fz">Developers</a></td></tr><tr><td>Just trying to connect</td><td><a href="/pages/FF3XWni6VUKhyXkecIYM">End Users</a></td></tr><tr><td>Interested in security or rewards</td><td><a href="/pages/DNAIyHpfL3jxRew8K164">Security</a> <mark style="color:$primary;">&#x26;</mark> <a href="/pages/B7662N9r4H0EJ9WB3ij9">Rewards</a></td></tr></tbody></table>

## What You Can Do With Anyone

* **Run a privacy-first relay** on your own terms
* **Integrate with Anyone SDK** across platforms
* **Connect to the network** from your favorite apps
* **Earn rewards** by contributing infrastructure
* **Fine-tune** your own secure, decentralized relay setup

Head to [Quick Start](/quickstart) to jump straight in to the installation and usage for your system

{% content-ref url="/pages/UuuNmacaToI0whRqk9tr" %}
[Quick Start](/quickstart)
{% endcontent-ref %}

## Need help?

Check out our [FAQ](/welcome/faq), join the [Community](/resources/links-and-whitepaper#links) or talk to our [Support](/resources/support#for-quick-access-to-our-ticket-support-visit-one-of-the-following-links) if you're stuck.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Relay Education</td><td><a href="/pages/A6GiZJ8YFa5GRz4iUReJ">/pages/A6GiZJ8YFa5GRz4iUReJ</a></td><td><a href="/files/1R3iU6aZHb6u1iehc7jB">/files/1R3iU6aZHb6u1iehc7jB</a></td></tr><tr><td align="center">Hardware Education</td><td><a href="/pages/k6E28mCFmvQDwrhPAGBy">/pages/k6E28mCFmvQDwrhPAGBy</a></td><td><a href="/files/h5EFCKqFulRs7pfGTOBL">/files/h5EFCKqFulRs7pfGTOBL</a></td></tr><tr><td align="center">Anyone SDK</td><td><a href="/pages/zTxDlieXqoE6Xs1YNj4p">/pages/zTxDlieXqoE6Xs1YNj4p</a></td><td><a href="/files/1gJUEi9zRNDcly6wzXNX">/files/1gJUEi9zRNDcly6wzXNX</a></td></tr><tr><td align="center">Connect to Anyone  </td><td><a href="/pages/FF3XWni6VUKhyXkecIYM">/pages/FF3XWni6VUKhyXkecIYM</a></td><td><a href="/files/XPUUQBMm1UF9gkUVqHFg">/files/XPUUQBMm1UF9gkUVqHFg</a></td></tr><tr><td align="center">Tokenomics</td><td><a href="/pages/Z1mIEVbCsSJ2evkj4We5">/pages/Z1mIEVbCsSJ2evkj4We5</a></td><td><a href="/files/Gvy7bCll1ot5xHrn0GOu">/files/Gvy7bCll1ot5xHrn0GOu</a></td></tr><tr><td align="center">Rewards</td><td><a href="/pages/B7662N9r4H0EJ9WB3ij9">/pages/B7662N9r4H0EJ9WB3ij9</a></td><td><a href="/files/XVeJsy3TerYcFvz0R9WR">/files/XVeJsy3TerYcFvz0R9WR</a></td></tr></tbody></table>

<table data-view="cards"><thead><tr><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>About</td><td><a href="/files/WBbbrOnSgjCQqaN5Ctz1">/files/WBbbrOnSgjCQqaN5Ctz1</a></td><td><a href="/pages/YiKlEbDkwwIXbRPXahqE">/pages/YiKlEbDkwwIXbRPXahqE</a></td></tr><tr><td>API Reference</td><td><a href="/files/UHwhdqsT753VIvjlrR3X">/files/UHwhdqsT753VIvjlrR3X</a></td><td><a href="/pages/ujE0NqYrwryX9B3eZWtd">/pages/ujE0NqYrwryX9B3eZWtd</a></td></tr><tr><td>Github</td><td><a href="/files/o9NaApM56QVUT2YV1QpQ">/files/o9NaApM56QVUT2YV1QpQ</a></td><td><a href="https://github.com/anyone-protocol">https://github.com/anyone-protocol</a></td></tr></tbody></table>


# About

The Anyone Protocol is the essential DePIN infrastructure that enables anyone to enjoy seamless privacy and data control, supported by on-chain incentives and signature hardware.

## An Introduction to Anyone

#### While data security and internet privacy have both seen tremendous growth in awareness over the past decade, the rampant collection of personal data by corporations only continues to grow. Internet users around the world are increasingly concerned about this pain point - that the 'profile' being built on them using their data is being used against them, both socially and monetarily. Furthermore, the widely accepted internet privacy solution - VPNs - simply shift the bottleneck and still log user activity, exposing users to hacks and leaks. The issue of internet privacy is highly pressing and suitable solutions that provide genuine privacy, without requiring complex user setup, simply don't exist at the scale and accessibility that they are needed.

#### The Anyone protocol is the universal solution to the mainstream online privacy problem. For the first time, we will deliver online privacy that people can trust completely and use seamlessly with any application.

#### The protocol is centered around its DePIN privacy layer - a traffic-routing network where all traffic is forwarded through multi-hop VPN tunnels. However, unlike VPNs, there is no need to 'trust' a central company to not track your internet activity. By encrypting each packet multiple times, in a process known as onion routing, the network ensures that no individual node, or the destination site, can infer a users' request.

#### The network is governed by an incentive protocol that provides operators with token rewards in accordance to Proof-of-Uptime, a novel consensus metric that tracks the bandwidth provided by a node, solving capacity problems faced by existing solutions in the past while also creating a new, accessible way for anyone to earn cryptocurrency by contributing bandwidth.&#x20;

#### Finally, Anyone delivers this privacy solution in a more universal way than before. It comes with an SDK to allow any developer to modify existing apps to route its traffic through the privacy layer, with no change to the user experience. Users can also run it locally and 'toggle' existing apps like browsers or games to auto-route through the network.

#### For a technical introduction, head over to the Whitepaper below

{% content-ref url="/pages/mawakHq96oAsVZwmITRf" %}
[Useful Links & Whitepaper](/resources/links-and-whitepaper)
{% endcontent-ref %}


# FAQ

[Anyone Protocol](#anyone-protocol)

[Contribution Rewards](#contribution-rewards)

[Relay Operations](#relay-operations)

[Relay Performance and Troubleshooting](#relay-performance-and-troubleshooting)

***

## Anyone Protocol

<details>

<summary>Does the Anyone Network integrate with other networks?</summary>

No, Anyone operates on its own privacy network and does not integrate directly with other networks. Though it is always possible to access the Internet through the Anyone network.

</details>

***

## Contribution Rewards

<details>

<summary>What rewards can I expect to earn from my relay?</summary>

While the minimum rewards emitted to relay operators is fixed, the amount of tokens you earn will be dependent both on the total number of relays and your own performance (as well as a number of other factors). Read the [Tokenomics](/tokenomics) to find out more.&#x20;

</details>

<details>

<summary>Why did I not receive my Airdrop rewards?</summary>

If you haven't received your redeemed rewards, here are a few steps to troubleshoot the issue:

1. [Check the Redemption Status](/dashboard/use#redeem-rewards): Ensure that the redemption process was completed successfully. Remember that ONLY rewards which were redeemed before the weekly deadline will be eligible for the airdrop.
2. Check you met the eligibility criteria. \
   \
   For non-hardware relays, 100 mainnet ANyONe tokens must be held for EACH relay associated with your wallet in a claimed state. Failure to meet this criterion will result in NONE of your redeemed rewards being eligible for the airdrop. The rewards for every period where this is the case will be forfeited.

</details>

<details>

<summary>Why do some of my relays earn more than others?</summary>

The earnings of your relays can vary due to several factors:\
\
1\. Consensus Weight: Each relay is assigned a consensus weight based on its measured bandwidth. Higher bandwidth typically means a higher consensus weight, leading to more rewards.\
\
2\. Uptime: Relays with consistent uptime are rewarded more. The network has uptime quality tiers, allocating 20% of rewards to relays with high uptime.\
\
3\. Relay Type: Different types of relays (e.g., hardware vs. virtual) may have different reward structures.\
\
4\. Geolocation and Relay Families: Rewards can be influenced by the relay's location and its association with relay families, which can affect network diversity and load balancing.

</details>

<details>

<summary>What is the purpose of the NFT?</summary>

When acquiring on of the first on thousand hardware devices, obtaining an Atornaut NFT is a prerequisite. This NFT isn't merely a digital collectible; it bestows a 100% bonus on relay rewards when staked. It entitles hardware relays to a bonus pool on top of normal relay rewards. Thus, possessing an NFT isn't solely about owning a digital asset; it's about enhancing earnings within the ecosystem and the only way to get one of the first devices.

You can find more information on the NFT on the mint page: [https://mint.ator.io](https://mint.ator.io/)

</details>

<details>

<summary>Do I need to lock up $ANYONE to register a relay?</summary>

Locking non-hardware relays requires 100 ANYONE per fingerprint.

Locking up tokens is not required for operators registering the [Anyone Router Hardware](/hardware/overview).

</details>

<details>

<summary>Can I use multiple wallet addresses?</summary>

No. It is forbidden to use multiple wallets for the relays you operate. All relays must be associated with the same wallet address. If you have multiple hardware relays, all NFTs must also be moved to the same wallet address.

</details>

<details>

<summary>How many relays can i run?</summary>

The total number of fingerprints allowed in one family is limited to the max allowed descriptor size which allows for around 400 fingerprints.

</details>

<details>

<summary>Why is my hardware relay not showing up properly on the dashboard?</summary>

The dashboard will only recognize and validate a fingerprint if:

* The Anyone Router hardware is updated the latest version
* It has an NFT ID and wallet added in the RCP
* The wallet associated with it holds this NFT on it.

When the Anyone Relay is validated as hardware it will not require locking 100 ANYONE, and will be designated as 'hardware'.

If the Anyone Relay is installed without the NFT ID, it will show up like non-hardware on the dashboard or not at all.

The logic as of now is that the only way to make sure the hardware is validated properly again, is to:

1\. Make sure the Anyone Relay is [updated to the latest version.](/hardware/hw-updates/update)

2\. First [add the NFT ID to the RCP](/hardware/setup-guides/controlpanel#relay-settings), apply and reboot. The NFT needs to be in the Ethereum address that is added to the RCP.

3\. [Lock, claim and then renounce the fingerprint](/dashboard/use).

4\. **Wait for a couple of hours** and the fingerprint should pop up again, recognized as **Hardware**.

This is due to the relay registration contract needing to update all the data again. This logic will be changed going forward before main net.

Read this for more information on how to use the rewards dashboard: <https://docs.anyone.io/rewards>

</details>

<details>

<summary>Why is my relay showing up against the wrong wallet in the dashboard?</summary>

If your relay is appearing against the wrong wallet then you must [renounce](/dashboard/use#renounce-relays) it in order to then [claim](/dashboard/use#claim-relays) it against the correct wallet address.&#x20;

And then go ahead and change the wallet address. \
See: [How do I change the wallet address associated with my relay? ](#how-do-i-change-the-wallet-address-associated-with-my-relay)

</details>

<details>

<summary>How do I change the wallet address associated with my relay?</summary>

First, make sure to update the relay with the correct wallet details.&#x20;

For Hardware Relays, do this via the [RCP](/hardware/setup-guides/controlpanel). \
For other relays, [update the Contact Info line in the anonrc file](/dashboard/register#adding-ethereum-wallet-address).&#x20;

Once you have done this, you must **restart** the relay for the changes to stick.&#x20;

Lastly, renounce the relay on the old wallet address. After a period of approximately 2-4 hours, the relay should appear against the correct wallet in the dashboard, available to lock and/or claim.

</details>

***

## Relay Operations

<details>

<summary>What is the purpose of the relay?</summary>

The Anyone Relay is the backbone of the entire privacy network. Whether run via software or our hardware, relays are the nodes that encrypt and forward users' traffic to anonymize it from both external participants and the relay itself. The performance and resilience of the Anyone Network is directly tied to the number of reliability of relays. Anyone can run a relay, contribute to the project and be incentivized for it.&#x20;

</details>

<details>

<summary>Can I run multiple relays or Can I run multiple Hardware Relays on my local network?</summary>

Yes, you can run multiple relays on your home network. Note however that multiple relays behind a single IP address may not necessarily result in a predictable increase in rewards, as they may compete with each other. For example, adding a second relay is unlikely to result in a two-fold increase in rewards. If possible, try to run your relays in different locations, as this benefits the network and is likely to result in higher consensus weights being achieved.

When running more than one relay it is required to configure your relays with [MyFamily](https://educ.ator.io/advanced-configuration/manual#myfamily-fingerprint-fingerprint-1).

</details>

<details>

<summary>How do I run a relay using my own device on my home network?</summary>

Full instructions on how to spin up your own Anyone relay from home are provided in the Anyone Docs here: <https://docs.anyone.io/relay>&#x20;

</details>

<details>

<summary>Can I run a relay if I have a dynamic IP address?</summary>

Yes, you can run a relay on your home network if you have a dynamic IP address. You may experience short periods of unreachability and subsequent changes in your consensus weight  and your relay’s flags when your IP address changes. For most users where changes are relatively infrequent, the impact of this should be minimal. There are some ISPs who will change your IP address on a very frequent basis, sometimes every 2-3 days. It should be noted that whilst this does not prevent you from running a relay, such frequent changes may prevent your relay from being seen as stable by the network, which in turn could have a negative impact on your consensus weight and rewards.

</details>

<details>

<summary>Do all VPS providers allow me to run a relay?</summary>

Not all VPS providers allow running relays. Some may have restrictions on bandwidth usage or running certain types of network services. It's important to check the terms of service of your chosen VPS provider to ensure they permit running a relay on their infrastructure. If in doubt, contact their support for clarification.

If you are considering running exit relays - we recommend you explicitly ask them before getting started.

</details>

<details>

<summary>Why do I need to declare my relays as a family?</summary>

Declaring your relays as a Relay Family is important for several reasons:

1. Network Integrity: It helps maintain the integrity of the Anyone Network by ensuring that multiple relays operated by the same entity are recognized as such. This transparency is crucial for preventing sybil attacks, where a single operator might try to unfairly influence the network by running multiple relays.
2. Reward Allocation: By declaring your relays as a family, you can optimise the allocation of rewards. The network can distribute rewards more fairly based on the collective performance and contribution of your relays.
3. Load Balancing: It aids in effective load balancing by allowing the network to understand the distribution and control of relays, ensuring that traffic is managed efficiently across the network.
4. Network Diversity: Encourages diversity in the network by clearly identifying and managing relays under a single operator, which helps in building a more robust and secure network.

By using the MyFamily option, you ensure that your relays are properly recognized and managed within the Anyone Network.

</details>

<details>

<summary>Can I backup and restore my fingerprint and keys?</summary>

**What to backup**:\
`/var/lib/anon/keys` - (the whole folder) \
`/etc/anon/anonrc` - (your config file) \
\
You can use something like WinSCP to connect to your relay via SSH (on Windows) and copy the files off.

**How to restore your backed-up keys**:\
Install the relay as per the normal installation instructions. As soon as the install is finished, stop the relay:

`systemctl stop anon`

Connect to the relay via WinSCP or other, and replace everything inside the keys folder and the config file:

`/var/lib/anon/keys` - (the whole folder) \
`/etc/anon/anonrc` - (your config file)

Now, to ensure you haven’t broken any ownership permissions by moving files etc, run:

`chown -R debian-anon:debian-anon /var/lib/anon`

Then startup your relay again:

`systemctl start anon`<br>

*Source:* [*Discord Community Post*](https://discord.com/channels/1083735132470521907/1084894795220123791/1258460430855180298)

</details>

<details>

<summary>How do I update my Hardware Relay?</summary>

You can find instructions on how to update your Hardware Relay, along with the latest update files here in the Anyone Docs&#x20;

[https://docs.anyone.io/hardware/update](/hardware/hw-updates/update)

</details>

<details>

<summary>How do I edit the anonrc configuration file in Debian?</summary>

You can use text editing tools like 'nano'.

`sudo apt-get install nano`

`sudo nano /etc/anon/anonrc`

Save and exit:

1. Press '**Ctrl+X**' to exit.
2. Press '**y**' and hit **ENTER** to confirm the changes.

</details>

<details>

<summary>How to install nyx for monitoring in Debian?</summary>

`sudo apt-get install nyx --yes`

To run Nyx, type: `sudo nyx`

*Note: see* [*Confirm ORPort Reachability*](/relay/troubleshooting/orport) *for more information on monitoring reachability.*\
\
To be able to use Nyx with your relay setup, remember to [enable ControlPort if you run the install-script](https://docs.anyone.io/welcome/pages/l1udV26vx6983G8YkdNa#id-6.-new-disable-or-enable-the-controlport-optional-choose-if-you-want-the-controlport-to-be-enabled-o) or [modify your anonrc configuration](/relay/start/install-anon-on-linux#edit-relay-configuration) to enable it afterwards.\
\
Read about [ControlPort](/sdk/native-sdk/manual#controlport-address-port-or-unix-path-or-auto-flags) in the [Manual](/sdk/native-sdk/manual) for more information on how it works.

</details>

<details>

<summary>How can I check that my relay is online?</summary>

### For hardware relays

1\. Access the Relay Control Panel (RCP):&#x20;

* Connect to the same network as your relay.
* Open a web browser and go to \`<http://relayup.local\\`>.
* Log in using the credentials:\
  &#x20;    \- Username: `relayup`\
  &#x20;    \- Password: `admin`\
  \
  2\. Check the 'Home' Page:
* Navigate to the 'Network' section.
* Look for the "Reachability" status indicated with "OR Port Reachable".
* If the status is 'OK' and 'Reachable', your relay is online and functioning properly.\
  \
  3\. Light Indicators:
* Ensure all lights on the relay are pulsing in the Anon Blue colour, indicating a successful setup.\
  \
  4\. Logs:
* Check the logs in the control panel for more details on the process.\
  \
  If everything checks out, congratulations! Your relay is online and ready to provide bandwidth to the Anyone Network.  If you encounter any issues, feel free to reach out for further assistance!

### Virtual relays

1. Install NYX and check for a message that your relay has confirmed reachability. You should also see flags start to appear if the relay is online and reachable.
2. Use the Anyone API to check your relay’s status by adding your fingerprint to the end of the following URL: <https://api.ec.anyone.tech/relays/>
3. Check the rewards dashboard and look for a green dot confirming the relay was online at the last check.

</details>

<details>

<summary>Does restarting my relay affect its recorded uptime?</summary>

Restarting your relay for short periods, like when installing updates, generally won't significantly impact your rewards. The Anyone Protocol rewards system considers uptime quality tiers, which focus on consistent uptime over longer periods. Brief downtimes for maintenance are expected and typically won't affect your relay's standing in these tiers. Just ensure your relay is back online promptly to maintain its performance and uptime record.

</details>

<details>

<summary>Why is my VPS relay not reachable?</summary>

Check if the datacenter's firewall is blocking the required ports. You may need to configure the firewall to allow traffic through the specific ports used by the relay.

</details>

<details>

<summary>Why is my relay not reachable?</summary>

If your relay is not reachable, there could be several reasons. Here are some common issues and solutions:

1. Firewall and Network Configurations: Ensure that your firewall settings allow traffic through the necessary ports. Check the [Firewall and Network Configurations section](/relay/network) for detailed instructions.
2. Router Port Forwarding: Your router might not be forwarding the required ports to your relay. Make sure port forwarding is correctly set up. Refer to the [Router Port Forwarding section](/relay/network/port-forward).
3. CGNAT Issues: If you're behind a Carrier-Grade NAT (CGNAT), it might block incoming connections. You can diagnose this issue in the [Diagnosing CGNAT and Public IPv4 section](/relay/troubleshooting/reachability).&#x20;
4. ORPort Reachability: Confirm that your ORPort is reachable from the outside. This is crucial for the relay to function properly. [Check the Confirm ORPort Reachability section.](/relay/troubleshooting/orport)

</details>

<details>

<summary>Is there a workaround for CGNAT?</summary>

If your ISP uses CGNAT, currently there is no workaround that will allow you to run a relay on your home network. You cannot use a VPN or WireGuard as a workaround.

Request a Public IP from Your ISP: Contact your ISP and request a dynamic or static public IP address. Some ISPs may charge for this service. Alternatively, consider running a relay on a VPS in a data center.

</details>

***

## Relay Performance and Troubleshooting

<details>

<summary>Why is my relay dropping its Flags?</summary>

When your relay is dropping its flags, it usually indicates an issue with its performance or configuration. Here are some common reasons and solutions:

1. Low Bandwidth or Uptime: Ensure your relay has a stable internet connection and meets the minimum bandwidth requirements. Consistent uptime is crucial for maintaining flags.
2. Configuration Issues: Double-check your relay's configuration settings. Incorrect settings can lead to flag drops. Make sure your relay is configured correctly according to the latest guidelines.
3. Network Changes: If your ISP changes your IP address frequently, it might affect your relay's stability. Consider using a static IP.
4. Resource Limitations: Ensure your device has enough resources (CPU, RAM) to handle the relay operations. Overloaded systems can cause performance issues.
5. Software Updates: Make sure your Anon software is up-to-date. Updates often include bug fixes and performance improvements.
6. Relay Reputation: If your relay has been flagged for suspicious activity or poor performance in the past, it might affect its current status. Ensure your relay complies with all network policies.

</details>

<details>

<summary>What does the Relay Flags mean?</summary>

In the Anyone Network, relays can be assigned various flags that indicate their roles or characteristics. Here are some common relay flags and their meanings:

1. Guard: This flag is given to relays that are suitable for being the first hop in a circuit. They have high uptime and reliability.
2. Exit: Relays with this flag allow traffic to exit the network to the internet. They follow specific exit policies.
3. Middle: These relays are used for the middle hops in a circuit. They don't have specific entry or exit roles.
4. Stable: Relays with this flag have been consistently online and reliable over a long period.
5. Fast: This flag is assigned to relays with high bandwidth, making them suitable for handling large amounts of traffic.
6. HSDir: These relays can store and serve hidden service descriptors, making them part of the hidden services infrastructure.
7. V2Dir: Relays with this flag can serve directory information to clients.

Each flag helps the network efficiently route traffic and maintain security and performance.

</details>

<details>

<summary>Why doesn’t my hardware relay pulse blue?</summary>

If your relay isn't pulsing in the Anon Blue colour, it might indicate an issue with the setup. Here are a few steps to troubleshoot:

1. Check Reachability: Ensure the "Reachability" status on the 'Home' page under the 'Network' section is 'OK'. If not, verify your port forwarding settings and ensure your router has a public IPv4 address and is not behind CGNAT. See <https://docs.anyone.io/relay/troubleshooting-common-issues> for further details.&#x20;
2. Review Logs: Check the logs in the Relay Control Panel for any error messages or warnings that might indicate what's wrong.
3. Network Configuration: Make sure your network settings are correctly configured, including any necessary port forwarding rules. <https://docs.anyone.io/relay/troubleshooting-common-issues/confirm-orport-reachability>
4. Update Software: Ensure your Anon software is updated to the latest version. Follow the update instructions carefully, especially regarding USB drive usage. <https://docs.anyone.io/hardware/updates>
5. Restart the Relay: Sometimes, a simple restart can resolve connectivity issues. Turn the relay off, save changes, reboot, then turn it on again, save changes, and reboot.

If these steps don't resolve the issue, feel free to join the Anyone Discord Community or raise a support ticket for further assistance!

</details>

<details>

<summary>How long does it take for my consensus weight to increase?</summary>

The increase in your consensus weight depends on several factors, including your relay's uptime and performance. Generally, it can take a few days to a couple of weeks for your relay to be recognized and for its consensus weight to adjust accordingly. Following this, the score may continue to increase for a period of weeks and months. Consistent uptime and maintaining good performance metrics are key to improving your consensus weight.

</details>

<details>

<summary>Why is my consensus weight so low?</summary>

Your consensus weight might be low due to several factors:

1. Bandwidth: Ensure your relay is providing sufficient bandwidth. The network measures and adjusts your consensus weight based on your relay's bandwidth performance.
2. Uptime: Consistent uptime is crucial. Relays with higher uptime are rewarded with better consensus weights.
3. Geolocation and Diversity: The network benefits from diverse relay locations. If your relay is in an area with many others, it might affect your weight.
4. Network Conditions: Temporary network conditions or changes in the network's overall load can also impact your consensus weight.

Remember, your bandwidth will show as zero when you first start your relay. Have patience over the first few days once you have confirmed the relay is online and reachable. You should see it increase after a couple of days have passed.

</details>

<details>

<summary>Why is my observed bandwidth low when my relay has a fast connection?</summary>

Firstly it is important that the speed of your relay is determined by the network, not simply the speed of your line. There could be several reasons why your observed bandwidth is low despite having a fast connection.

It is important to note that the speed displayed in the rewards dashboard uses MiB/s (Mebibytes per second) not megabits per second. A reported Observed Bandwidth of 10 MiB/s is equivalent to approximately 84 megabits per second.

1\. Configuration Settings: Ensure that your RelayBandwidthRate and RelayBandwidthBurst settings are configured correctly. These settings control the maximum bandwidth your relay can use.\
\
2\. Network Congestion: Other devices on your network might be using bandwidth, causing congestion. Check if other applications or devices are consuming significant bandwidth.\
\
5\. Relay Uptime: Consistent uptime is crucial. If your relay frequently disconnects, it might not be fully utilised by the network.\
\
6\. Network Diversity: The Anyone Network benefits from diverse relay locations. If there are many relays in your area, traffic might be distributed among them, affecting your observed bandwidth.\
\
7\. Consensus Weight: Your relay's consensus weight might be low. This score affects how much traffic your relay receives. It can be influenced by factors like uptime and bandwidth measurements.\
\
8\. Hardware Limitations: Ensure your hardware can handle the relay's demands. While the Anyone Relay doesn't require high CPU/GPU power, it still needs reliable hardware.

9\. Up-speed is key. Traffic on the Anyone network is typically synchronous i.e., your relay will send and receive roughly the same volume of data. The up-speed of your internet service is therefore likely to determine the observed bandwidth your relay is able to achieve, not your down-speed.

</details>

<details>

<summary>Why does my relay say ‘client not installed’?</summary>

If your relay is indicating that the client is not installed, it could be due to a few reasons. Here are some steps to troubleshoot:\
\
1\. Check Installation: Ensure that the Anon Client is properly installed on your device. You can verify this by checking if the \`bin/anon\` binary is present. If the client is not installed, try to trigger an install in the RCP. Go to Relay settings and turn the Relay OFF, save changes, reboot, then turn it ON again, save changes, and reboot. Recheck the status in the Relay Control Panel. If the problem persists, raise a support ticket for further help.

2\. Network Connection: Make sure your relay is connected to the internet, either via Ethernet or WiFi. A lack of connection might prevent the client from being installed.\
\
3\. Software Update: Ensure your relay is running the latest software version. You can update it by downloading the latest version from the official site and following the update instructions.\
\
4\. Logs: Check the logs in the control panel for any error messages that might give more insight into the issue.\
\
If these steps don't resolve the issue, feel free to reach out to the Anyone Discord Community for further assistance, or raise a support ticket.

</details>


# Quick Start

Choose how you want to connect or build with **Anyone**.\
\
Each path takes you to a short setup guide with everything you need to get started in minutes.

***

**Linux / VPS**

Run a relay or connect directly from your own server.\
🔗 Go to [Linux / VPS Setup](/relay/start/install-anon-on-linux)

***

**macOS**

Set up with one click or use the NPM SDK for full control.\
🔗 Go to[ macOS Setup](/connect/macos)

***

**Windows**

Use our One-Click Installer or run Anon through PowerShell.\
🔗 Go to [Windows Setup](/connect/windows)

***

**iOS**

Use the Anyone iOS app or integrate through the iOS SDK (Beta).\
🔗 Go to [iOS Setup](/connect/ios)

***

**Android**

Connect instantly through the Android app (coming soon).\
🔗 Go to [Android Setup](/connect/android)&#x20;

***

**Hardware Router**

Plug in, power up, and route your entire network through Anyone.\
🔗 Go to [Hardware Quick Start](/hardware)&#x20;

***

**Developers / SDK**

Integrate Anyone directly into your app using our SDKs and APIs.\
🔗 Go to [Developer SDKs](/sdk)&#x20;

{% hint style="info" %}

#### 💡 Tip

#### Not sure where to start?

Check out our [Overview](/) for more information.
{% endhint %}


# Relay Setup

This Relay Educator Series is intended to help you set up a Relay in the Anon network to earn recognition rewards in exchange for bandwidth and layered encryption of network traffic.

## Welcome to the Anyone Relay Setup Docs!&#x20;

Anyone's core vision is to make true privacy the reality for every mainstream internet user. The key to this vision is DePIN - a decentralized infrastructure of nodes around the world that make up the Anon Network. But no DePIN is complete without its node operators.

If you are here to learn, teach and help build the privacy network for anyone, you have come to the right place! The Relay Setup pages are a set of living docs to help you run a relay in the Anon Network, use the network and earn decentralized rewards.&#x20;

**Ready to #RelayUp?**

<table data-view="cards"><thead><tr><th></th><th data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>Setting up Anyone Router Hardware? Go to</td><td><a href="/pages/k6E28mCFmvQDwrhPAGBy">/pages/k6E28mCFmvQDwrhPAGBy</a></td><td><a href="/files/zk5NZlXtd7A8pzkWXzVU">/files/zk5NZlXtd7A8pzkWXzVU</a></td><td><a href="/pages/k6E28mCFmvQDwrhPAGBy">/pages/k6E28mCFmvQDwrhPAGBy</a></td></tr><tr><td>Ready to dive in? Head over to</td><td><a href="/pages/AWPTxAeEmwViLBHULgmP">/pages/AWPTxAeEmwViLBHULgmP</a></td><td><a href="/files/1gJUEi9zRNDcly6wzXNX">/files/1gJUEi9zRNDcly6wzXNX</a></td><td><a href="/pages/eyMNCk63xJ3RZBOTW0xy">/pages/eyMNCk63xJ3RZBOTW0xy</a></td></tr><tr><td>Have questions or stuck? Go to:</td><td><a href="/pages/BJQdsq2QEm1BU3ffCSNR">/pages/BJQdsq2QEm1BU3ffCSNR</a></td><td><a href="/files/a1ho2o4ZnVvWWw4zyus1">/files/a1ho2o4ZnVvWWw4zyus1</a></td><td><a href="/pages/BJQdsq2QEm1BU3ffCSNR">/pages/BJQdsq2QEm1BU3ffCSNR</a></td></tr></tbody></table>


# Install & Configure

Setting Your Environment to operate a Relay

## Welcome! <a href="#welcome" id="welcome"></a>

Relays in the Anyone Network run the **anon** binary. This is currently designed for Linux operating systems, unlike the more mainstream macOS and Windows commonly found on home computers. However, there are several options available for running anon on various machines, with even more coming in the future.

Have a **Debian** based installation? Skip straight to [#anon-debian-quick-install](#anon-debian-quick-install "mention"). If not, continue below to setup your environment.&#x20;

## First thing first: Set Up Your Environment <a href="#first-thing-first-set-up-your-environment" id="first-thing-first-set-up-your-environment"></a>

In the first steps of this Relay Series you can choose the best option for setting up your environment for relaying and encrypting internet traffic, and then proceed to the installation chapter, configure the relay for the network you are using it in and participate in the rewards Program.&#x20;

**Let's get started, select a tutorial..**

<table data-column-title-hidden data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center">Debian and Ubuntu</td><td><a href="/files/DgFapWAudPpPxg4BuJdZ">/files/DgFapWAudPpPxg4BuJdZ</a></td><td><a href="/pages/vFLHg9BUxPr2iYoXF1qH#operating-system">/pages/vFLHg9BUxPr2iYoXF1qH#operating-system</a></td></tr><tr><td align="center">Windows</td><td><a href="/files/3vF3I74SBREJUhpRMI00">/files/3vF3I74SBREJUhpRMI00</a></td><td><a href="/pages/vFLHg9BUxPr2iYoXF1qH#hardware-virtualization">/pages/vFLHg9BUxPr2iYoXF1qH#hardware-virtualization</a></td></tr><tr><td align="center">MacOS</td><td><a href="/files/l01OjaaixXFs33NTu5Z3">/files/l01OjaaixXFs33NTu5Z3</a></td><td><a href="/pages/vFLHg9BUxPr2iYoXF1qH#hardware-virtualization">/pages/vFLHg9BUxPr2iYoXF1qH#hardware-virtualization</a></td></tr><tr><td align="center">Docker</td><td><a href="/files/5dWEq17Xg3WUhRXcv7UP">/files/5dWEq17Xg3WUhRXcv7UP</a></td><td><a href="/pages/qt8fW6E5d7ob2BpvZZ0D">/pages/qt8fW6E5d7ob2BpvZZ0D</a></td></tr><tr><td align="center">SDK</td><td><a href="/files/CMs9q5OrnS6fbv6ab5MP">/files/CMs9q5OrnS6fbv6ab5MP</a></td><td><a href="/pages/1bSSmNfC2F72PV3GDuQ0">/pages/1bSSmNfC2F72PV3GDuQ0</a></td></tr><tr><td align="center">Anyone Relay</td><td><a href="/files/96cC79cj2rtJubDhXRWa">/files/96cC79cj2rtJubDhXRWa</a></td><td><a href="/pages/k6E28mCFmvQDwrhPAGBy">/pages/k6E28mCFmvQDwrhPAGBy</a></td></tr></tbody></table>

***

## Anyone Debian Quick install <a href="#anon-debian-quick-install" id="anon-debian-quick-install"></a>

If you are running a Debian-based distribution, you can use the method below to copy and execute a bash script in your terminal prompt to install the anon package instantly. After installation, you'll be prompted with some follow-up questions to configure your relay.

{% code title="Copy ->" overflow="wrap" %}

```bash
sudo /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/anyone-protocol/anon-install/refs/heads/main/install.sh)"
```

{% endcode %}

**See the Linux installation page for a more descriptive instruction and examples of the input.**

{% content-ref url="/pages/l1udV26vx6983G8YkdNa" %}
[Installing Anon](/relay/start/install-anon-on-linux)
{% endcontent-ref %}

## Visit some of the other popular pages..

<table data-column-title-hidden data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Rewards Program</td><td><a href="/pages/rhCcL6zm8kH4vyJeYwR7">/pages/rhCcL6zm8kH4vyJeYwR7</a></td><td><a href="/files/w6vEIvamlASo2L1FjbfB">/files/w6vEIvamlASo2L1FjbfB</a></td></tr><tr><td align="center">Frequently Asked Questions</td><td><a href="/pages/zHjwglSNxwXYvTqdZYQ5">/pages/zHjwglSNxwXYvTqdZYQ5</a></td><td><a href="/files/pdxyruKWixMKIgy9hp1z">/files/pdxyruKWixMKIgy9hp1z</a></td></tr><tr><td align="center">Customer Support</td><td><a href="/pages/cw4ot6GACuqhoDFkHGrF">/pages/cw4ot6GACuqhoDFkHGrF</a></td><td><a href="/files/FEUZDBQru0p0sIV33lTT">/files/FEUZDBQru0p0sIV33lTT</a></td></tr><tr><td align="center">Official Links</td><td><a href="/pages/mawakHq96oAsVZwmITRf">/pages/mawakHq96oAsVZwmITRf</a></td><td><a href="/files/sfxOdMuIDrDAXjD6nRgc">/files/sfxOdMuIDrDAXjD6nRgc</a></td></tr><tr><td align="center">Terms of Service</td><td><a href="https://www.anyone.io/terms">https://www.anyone.io/terms</a></td><td><a href="/files/iQh3lBKYau377rk862CR">/files/iQh3lBKYau377rk862CR</a></td></tr><tr><td align="center"></td><td></td><td></td></tr></tbody></table>

***

This page helps you find links to Virtualization guides on Windows and macOS or Ubuntu Server Installation Guide. Next step, after that, install the anon Software and sign up for rewards.

## Hardware Virtualization <a href="#hardware-virtualization" id="hardware-virtualization"></a>

There are a couple of options for running a relay on different Operating Systems, utilizing Virtualization is one of them. This guide will instruct you on how to install a Virtualization tool in for different Operating Systems as well as creating a Virtual Machine running Ubuntu Server 22.04 LTS, which the Anon Relay software later on can be installed on.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Virtualization for Windows</td><td><a href="/pages/YG9S3OPkI98AoejizU6W">/pages/YG9S3OPkI98AoejizU6W</a></td><td><a href="/files/3vF3I74SBREJUhpRMI00">/files/3vF3I74SBREJUhpRMI00</a></td></tr><tr><td align="center">Virtualization for macOS</td><td><a href="/pages/E6xdN8VJfAiM74OrADWB">/pages/E6xdN8VJfAiM74OrADWB</a></td><td><a href="/files/l01OjaaixXFs33NTu5Z3">/files/l01OjaaixXFs33NTu5Z3</a></td></tr></tbody></table>

***

## Operating system <a href="#operating-system" id="operating-system"></a>

For help installing a reliable and versatile Debian-based operating system, we offer a Ubuntu Server Installation Guide.

Follow step-by-step instructions for installing Ubuntu Server 22.04, a robust platform renowned for its stability, security, and extensive support for a wide range of applications and services.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Install Ubuntu Server 22.04 LTS</td><td><a href="/pages/7LP3OacWNVzmP2uGtjJ4">/pages/7LP3OacWNVzmP2uGtjJ4</a></td><td><a href="/files/DgFapWAudPpPxg4BuJdZ">/files/DgFapWAudPpPxg4BuJdZ</a></td></tr></tbody></table>

***

## Remote Management <a href="#remote-management" id="remote-management"></a>

SSH (Secure Shell) is a tool for securely managing remote servers. It allows you to log in to a server from your local machine and execute commands as if you were sitting at the server's console.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">SSH in Windows and macOS</td><td><a href="/pages/KNBmUeIsZrVSBTrzMu1i">/pages/KNBmUeIsZrVSBTrzMu1i</a></td><td><a href="/files/CMs9q5OrnS6fbv6ab5MP">/files/CMs9q5OrnS6fbv6ab5MP</a></td></tr></tbody></table>

***

### CLI Software <a href="#software" id="software"></a>

Once you've set up your hardware virtualization or dedicated hardware and installed a Debian-based Linux Operating System like the Ubuntu Server from the guide above, let's install the Anon Relay Software with a one-line bash script or following the [apt resources](/relay/start/install-anon-on-linux/apt).

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Install anon on Linux</td><td><a href="/pages/l1udV26vx6983G8YkdNa">/pages/l1udV26vx6983G8YkdNa</a></td><td><a href="/files/oji2lsciVjsi5dSYIh07">/files/oji2lsciVjsi5dSYIh07</a></td></tr></tbody></table>

***

## Token Rewards <a href="#rewards" id="rewards"></a>

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Registering to the Rewards Program</td><td><a href="/pages/HOIqKCSwQda5LU1TR66Q">/pages/HOIqKCSwQda5LU1TR66Q</a></td><td><a href="/files/Gvy7bCll1ot5xHrn0GOu">/files/Gvy7bCll1ot5xHrn0GOu</a></td></tr><tr><td align="center">Accessing the Relay Dashboard</td><td><a href="/pages/rhCcL6zm8kH4vyJeYwR7">/pages/rhCcL6zm8kH4vyJeYwR7</a></td><td><a href="/files/w6vEIvamlASo2L1FjbfB">/files/w6vEIvamlASo2L1FjbfB</a></td></tr></tbody></table>


# OS Environment Prep

This page helps you find links to Virtualization guides on Windows and macOS or Ubuntu Server Installation Guide. Next step, after that, install the anon Software and sign up for rewards.

## Hardware Virtualization <a href="#hardware-virtualization" id="hardware-virtualization"></a>

There are a couple of options for running a relay on different Operating Systems, utilizing Virtualization is one of them. This guide will instruct you on how to install a Virtualization tool in for different Operating Systems as well as creating a Virtual Machine running Ubuntu Server 22.04 LTS, which the Anon Relay software later on can be installed on.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Virtualization for Windows</td><td><a href="/pages/YG9S3OPkI98AoejizU6W">/pages/YG9S3OPkI98AoejizU6W</a></td><td><a href="/files/3vF3I74SBREJUhpRMI00">/files/3vF3I74SBREJUhpRMI00</a></td></tr><tr><td align="center">Virtualization for macOS</td><td><a href="/pages/E6xdN8VJfAiM74OrADWB">/pages/E6xdN8VJfAiM74OrADWB</a></td><td><a href="/files/l01OjaaixXFs33NTu5Z3">/files/l01OjaaixXFs33NTu5Z3</a></td></tr></tbody></table>

***

## Operating system <a href="#operating-system" id="operating-system"></a>

For help installing a reliable and versatile Debian-based operating system, we offer a Ubuntu Server Installation Guide.

Follow step-by-step instructions for installing Ubuntu Server 22.04, a robust platform renowned for its stability, security, and extensive support for a wide range of applications and services.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Install Ubuntu Server 22.04 LTS</td><td><a href="/pages/7LP3OacWNVzmP2uGtjJ4">/pages/7LP3OacWNVzmP2uGtjJ4</a></td><td><a href="/files/DgFapWAudPpPxg4BuJdZ">/files/DgFapWAudPpPxg4BuJdZ</a></td></tr></tbody></table>

***

## Remote Management <a href="#remote-management" id="remote-management"></a>

SSH (Secure Shell) is a tool for securely managing remote servers. It allows you to log in to a server from your local machine and execute commands as if you were sitting at the server's console.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">SSH in Windows and macOS</td><td><a href="/pages/KNBmUeIsZrVSBTrzMu1i">/pages/KNBmUeIsZrVSBTrzMu1i</a></td><td><a href="/files/CMs9q5OrnS6fbv6ab5MP">/files/CMs9q5OrnS6fbv6ab5MP</a></td></tr></tbody></table>

***

### CLI Software <a href="#software" id="software"></a>

Once you've set up your hardware virtualization or dedicated hardware and installed a Debian-based Linux Operating System like the Ubuntu Server from the guide above, let's install the Anon Relay Software with a one-line bash script or following the apt resources.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Install anon on Linux</td><td><a href="/pages/l1udV26vx6983G8YkdNa">/pages/l1udV26vx6983G8YkdNa</a></td><td><a href="/files/oji2lsciVjsi5dSYIh07">/files/oji2lsciVjsi5dSYIh07</a></td></tr></tbody></table>

***

## Rewards <a href="#rewards" id="rewards"></a>

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td align="center">Registering to the Rewards Program</td><td><a href="/pages/HOIqKCSwQda5LU1TR66Q">/pages/HOIqKCSwQda5LU1TR66Q</a></td><td><a href="/files/Gvy7bCll1ot5xHrn0GOu">/files/Gvy7bCll1ot5xHrn0GOu</a></td></tr><tr><td align="center">Accessing the Relay Dashboard</td><td><a href="/pages/rhCcL6zm8kH4vyJeYwR7">/pages/rhCcL6zm8kH4vyJeYwR7</a></td><td><a href="/files/w6vEIvamlASo2L1FjbfB">/files/w6vEIvamlASo2L1FjbfB</a></td></tr></tbody></table>


# Virtualization

This page will guide you on how to install the VirtualBox virtualization tool on Windows and MacOS and how to create a Virtual Machine running Ubuntu Server 22.04 LTS.

## Table of Contents

[Windows](#prepare-installation-files-for-the-vm)

[MacOS](#macos)

Linux  (To be Added)

{% hint style="info" %}
Some operators opt not to use virtualization and instead choose dedicated hardware such as the [**Anyone Router**](/hardware), a **standalone device**, a **Virtual Private Server** (VPS), or an **arm64 microcontroller** like a Raspberry Pi. In such cases, the Anon Relay can be installed directly on the operating system by first installing Debian or Ubuntu and then setting up the `anon` package using bash - no virtualization required.
{% endhint %}

***

## Windows <a href="#prepare-installation-files-for-the-vm" id="prepare-installation-files-for-the-vm"></a>

### Prepare Installation files for the VM <a href="#prepare-installation-files-for-the-vm" id="prepare-installation-files-for-the-vm"></a>

Download Ubuntu Server from the official Ubuntu website by following the link below. On the website, click the "**Download**" button to retrieve the file named "**ubuntu-\<version>-live-server-amd64.iso"**.

{% embed url="<https://ubuntu.com/download/server>" %}

<div align="left"><figure><img src="/files/rcWk97voXsvwuUe450iu" alt="" width="375"><figcaption></figcaption></figure></div>

### **1. Download VirtualBox** <a href="#id-1.-download-virtualbox" id="id-1.-download-virtualbox"></a>

Download VirtualBox from the official website: <https://www.virtualbox.org/wiki/Downloads>. Select the package that matches your operating system. VirtualBox is compatible with Windows, macOS (Intel only), and Linux.

{% hint style="warning" %}
The Operating System must have [Microsoft Visual C++ Redistributable 2019](https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170#visual-studio-2015-2017-2019-and-2022) installed and Virtualization [enabled in BIOS](https://support.microsoft.com/en-us/windows/enable-virtualization-on-windows-11-pcs-c5578302-6e43-4b4b-a449-8ced115f58e1)
{% endhint %}

<div align="left"><figure><img src="/files/Jdop929gb4zPHONSFKUk" alt="" width="375"><figcaption></figcaption></figure></div>

### **2. Install VirtualBox** <a href="#id-2.-install-virtualbox" id="id-2.-install-virtualbox"></a>

Execute the installer and adhere to the on-screen prompts to install VirtualBox on your computer. The installation steps may differ based on your operating system, but it's typically a straightforward process. Ensure you read and agree to the license agreement as part of the installation procedure.

<div align="left"><figure><img src="/files/dnucJvjgp6ZwKDM3XjC2" alt="" width="371"><figcaption></figcaption></figure></div>

### **3. Launch VirtualBox** <a href="#id-3.-launch-virtualbox" id="id-3.-launch-virtualbox"></a>

Once the installation is finished, open VirtualBox. The VirtualBox Manager window, the primary interface for managing your virtual machines, should appear.

<div align="left"><figure><img src="/files/04LsikVfrySWvwnWkHlx" alt="" width="375"><figcaption></figcaption></figure></div>

### **4. Create a New Virtual Machine** <a href="#id-3.-create-a-new-virtual-machine" id="id-3.-create-a-new-virtual-machine"></a>

In the VirtualBox Manager window, click on 'New' to initiate the creation of a new virtual machine.

<div align="left"><figure><img src="/files/xcwAg3We9xiEPUnqjMMY" alt="" width="375"><figcaption></figcaption></figure></div>

### **5. Configure the Virtual Machine:** <a href="#id-4.-configure-the-virtual-machine" id="id-4.-configure-the-virtual-machine"></a>

a. Provide a preferred **name** for your virtual machine\
b. Browse and select the **ISO image** downloaded in preparation \
c. Check the box for '**Skip Unattended Installation'** \
d. Allocate Memory (RAM); a minimum of **2 GB** is sufficient \
e. Allocate processors (CPU); a minimum of **2 CPU** is sufficient \
f. Choose disk size; a minimum of **15GB** is sufficient \
g. Press '**Finish**' when all changes have been made

<div align="left"><figure><img src="/files/kyMD9UQkMyC0mMMXpeG7" alt="" width="375"><figcaption></figcaption></figure></div>

### 6. Edit the Network Adapter for the Virtual Machine: <a href="#id-5.-edit-the-network-adapter-for-the-virtual-machine" id="id-5.-edit-the-network-adapter-for-the-virtual-machine"></a>

a. Right-click the Virtual Machine, select '**Settings**', and go to the '**Network'** tab. \
b. Change '**Attached to:**' to '**Bridged Adapter**.'

Depending if you want your VM to use Wireless or wired Ethernet Connection, change '**Name**' to the adapter of your choice and keep in mind that this name may vary depending on your hardware.

<div align="left"><figure><img src="/files/tYUcrFOhOjteUYP1EOWa" alt="" width="375"><figcaption></figcaption></figure></div>

### 7. Detachable Start <a href="#id-6.-detachable-start" id="id-6.-detachable-start"></a>

Click the small arrow next to '**Start**' and choose '**Detachable Start**'. This allows you to close the console window later on.

<div align="left"><figure><img src="/files/SyexZu7KewgIqAw4AxYG" alt="" width="375"><figcaption></figcaption></figure></div>

***

## MacOS

{% hint style="info" %}
Some operators opt **not** to use **virtualization** and instead choose dedicated hardware such as the [Anyone Router Hardware](/hardware), a **standalone** device, a **Virtual Private Server** (VPS), or an **arm64 microcontroller** like a Raspberry Pi. In such cases, the **Anon Relay** can be installed directly on the operating system without virtualization by installing **Debian** or **Ubuntu** and setting up the **anon** package with bash.
{% endhint %}

### Prepare Installation files for the VM <a href="#prepare-installation-files-for-the-vm" id="prepare-installation-files-for-the-vm"></a>

Start by downloading the **Ubuntu Server** image for **arm64**. Visit the website below and select "**Download Ubuntu Server 22.04 LTS**".

{% embed url="<https://ubuntu.com/download/server/arm>" %}

### 1. Download Virtualization Software <a href="#id-1.-download-virtualization-software" id="id-1.-download-virtualization-software"></a>

Download the UTM package from their website, then open the downloaded UTM.dmg file.

{% embed url="<https://mac.getutm.app/>" %}

### 2. Start Software installation

When prompted, drag the **UTM.app** icon to the **Applications** folder to **install UTM**.

<div align="left"><figure><img src="/files/kY7WfeH30O0GZQwzyest" alt="" width="563"><figcaption></figcaption></figure></div>

### 3. Create a new Virtual Machine to Virtualize <a href="#id-3.-create-a-new-virtual-machine-to-virtualize" id="id-3.-create-a-new-virtual-machine-to-virtualize"></a>

Start the **UTM** application and choose "**Create a New Virtual Machine**", then select "**Virtualize**".

<div align="left"><figure><img src="/files/3HVbaCsbB4vMYXeVE7kT" alt="" width="563"><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/8Ull0yJIvuXzHvTIh2ms" alt="" width="563"><figcaption></figcaption></figure></div>

### 4. Select **Linux**

<div align="left"><figure><img src="/files/3K73zyANrYDgiXTTbpp1" alt="" width="563"><figcaption></figcaption></figure></div>

### 5. Specify the VM installation file

Select "**Browse...**" and locate the previously downloaded **Ubuntu Server** image.

<div align="left"><figure><img src="/files/wbg0Z6ipzDxZyOc7aqbb" alt="" width="563"><figcaption></figcaption></figure></div>

### 6. Adjust System Resources

Select the amount of **Memory** and **CPU** cores to allocate to your **Virtual Machine**.&#x20;

The recommended minimum requirements are:

* **2048 MB RAM Memory**
* **2 CPU Cores**

These parameters can also be adjusted later on if needed by powering off your VM and editing the settings before turning it on again.

<div align="left"><figure><img src="/files/gVGi52aqAKtRVOGzHi7V" alt="" width="563"><figcaption></figcaption></figure></div>

### 7. Specify the **Storage space**. <a href="#id-7.-specify-the-storage-space" id="id-7.-specify-the-storage-space"></a>

**15 GB** is sufficient for Ubuntu Server 22.04 LTS. This parameter can also be adjusted later on if needed.

<div align="left"><figure><img src="/files/JFEzaCpkYjqXz644IiTb" alt="" width="563"><figcaption></figcaption></figure></div>

### 8. Set a Name

Specify the preferred **Name** of your Virtual Machine, then check the box **Open VM Settings** and click **Save**.

<div align="left"><figure><img src="/files/lhb7pCDLouPKpUguOYvR" alt="" width="563"><figcaption></figcaption></figure></div>

### 9. Network Interface Settings

Go to the **Network** section and change the **Network Mode** to **Bridged (Advanced)**, then press **Save**.

<div align="left"><figure><img src="/files/obnTYxfjPQSr5KfwgD6m" alt="" width="563"><figcaption></figcaption></figure></div>

### 10. Start the VM

Click on the **Play** icon to start the **Virtual Machine**

<div align="left"><figure><img src="/files/twdOYDpN7pdxkhBALXka" alt="" width="563"><figcaption></figcaption></figure></div>

## Next step <a href="#next-step" id="next-step"></a>

To continue the installation of the Operating System **Ubuntu Server 22.04** on your **VM**, visit the following page:

{% content-ref url="/pages/7LP3OacWNVzmP2uGtjJ4" %}
[Ubuntu 24.04](/relay/start/prep/ubuntu)
{% endcontent-ref %}


# Ubuntu 24.04

This page will guide you through the installation of Ubuntu Server, either on your Virtual Machine or directly on dedicated hardware.

If you haven't already booted the Ubuntu Server image in previous steps you can find and download the Ubuntu Server 24.04 LTS image below.

{% embed url="<https://ubuntu.com/download/server>" %}

### 1.   Start the Installation

After booting from the Ubuntu Server image, choose "Try or Install Ubuntu Server".

<div align="left"><figure><img src="/files/q1GhN0kwAFqMJCTASAW7" alt="" width="360"><figcaption></figcaption></figure></div>

### 2.   Choose system language

Select your preferred system language.

<div align="left"><figure><img src="/files/3Uri41pArOVUjM9ROBwu" alt="" width="322"><figcaption></figcaption></figure></div>

### 3.   Installer update available

Select 'Update to the new installer'.

<div align="left"><figure><img src="/files/CVPLR77K5YGjwQ1Q2Xhl" alt="" width="323"><figcaption></figcaption></figure></div>

### 4.   Keyboard configuration

Select your preferred keyboard layout.

<div align="left"><figure><img src="/files/A3B730aGV27fPgomMIIb" alt="" width="324"><figcaption></figcaption></figure></div>

### 5.   Choose type of installation

Make sure "**Ubuntu Server**" is checked and then select '**Done**'.

<div align="left"><figure><img src="/files/IzZJdjL7Ra6nhfHSW3UM" alt="" width="324"><figcaption></figcaption></figure></div>

### 6.   Network connections

Wait until DHCPv4 assigns a LAN IP and make **note** of it for upcoming steps then select '**Done**'.

<div align="left"><figure><img src="/files/T3HgMq3kptnwLFNSXdEO" alt="" width="326"><figcaption></figcaption></figure></div>

### 7.   Configure proxy

Leave the field empty and select '**Done**'.

### 8.   Configure Ubuntu archive mirror

When mirror tests passed, select '**Done**'.

### 9.   Guided storage configuration

Keep the default settings and select '**Done**'.

### 10.   Storage configuration

Keep the default settings and select '**Done**', then confirm by selecting '**Continue**'.

### 11.   Profile setup

Set your preferred system information. Save the '**username**' and '**password**' for future reference.

<div align="left"><figure><img src="/files/gaL8MBlERaroYWXiCgfp" alt="" width="328"><figcaption></figcaption></figure></div>

### 12.   Upgrade to Ubuntu Pro

Select '**Skip for now'**.

### 13.   SSH Setup

Check '**Install OpenSSH server'** and then select '**Done'**.

<div align="left"><figure><img src="/files/Exp4SgMEIFQZxDJLy0oa" alt="" width="323"><figcaption></figcaption></figure></div>

### 14.   Featured Server Snaps

Leave everything unchecked and select '**Done**'.

<div align="left"><figure><img src="/files/MQ5jiu8Y9MtGDF1hkzo7" alt="" width="328"><figcaption></figcaption></figure></div>

### 15.   When '**Reboot Now'** is prompted the Installation is complete!

Select '**Reboot Now'.**

<div align="left"><figure><img src="/files/nxqtJfcBVmpOPWbrPgq2" alt="" width="325"><figcaption></figcaption></figure></div>

### 16.  Getting the message: "Failed unmounting /cdrom"

Press **ENTER** to start the VM.

<div align="left"><figure><img src="/files/vyPi8lHhk9uQ0gPHYD90" alt="" width="340"><figcaption></figcaption></figure></div>

***

## Next step

#### For managing your relay it is recommended to connect to it over SSH. Go to the page below to learn how:

{% content-ref url="/pages/KNBmUeIsZrVSBTrzMu1i" %}
[SSH setup](/relay/start/prep/ssh-setup)
{% endcontent-ref %}

#### To continue the installation of the the Anon Relay Software on your **VM**, visit the following page:

{% content-ref url="/pages/l1udV26vx6983G8YkdNa" %}
[Installing Anon](/relay/start/install-anon-on-linux)
{% endcontent-ref %}


# SSH setup

SSH (Secure Shell) is a tool for securely managing remote servers. It allows you to log in to a server from your local machine and execute commands as if you were sitting at the server's console

{% tabs %}
{% tab title="Windows PowerShell" %}
**How to use SSH with PowerShell in Windows?**

* Search for "**PowerShell**" in the Start menu and select it.
* Type `ssh username@ip_address` in PowerShell, replacing "username" with your username and "ip\_address" with the IP address of your server.
  * First time you access a confirmation of the fingerprint is required, confirm fingerprint by typing "**yes**" then hit enter.
* If prompted, enter the password for your user account.
* Once authenticated, you're connected to your Linux device via SSH in PowerShell. You can now execute commands directly from PowerShell.

{% embed url="<https://www.youtube.com/watch?v=PX7PPVav3rs>" %}
{% endtab %}

{% tab title="macOS Terminal" %}
**How to use SSH with Terminal in macOS?**

* Search for "**Terminal**" in Applications and select it.
* Type `ssh username@ip_address` in Terminal, replacing "username" with your username and "ip\_address" with the IP address of your server.
  * First time you access a confirmation of a the fingerprint is required, confirm fingerprint by typing "**yes**" then hit enter.
* If prompted, enter the password for your user account.
* Once authenticated, you're connected to your Linux device via SSH in Terminal. You can now execute commands directly from Terminal.

{% embed url="<https://www.youtube.com/watch?v=zA-POlxMxRk>" %}
{% endtab %}
{% endtabs %}


# Installing Anon

This guide walks you through the process of installing and configuring the Anyone Relay on a Debian based x86 or arm64 Linux systems and support for more distributions will follow in a near future.

The Anyone Relay is a critical component of the **Anyone Protocol**, which ensures anonymity and privacy in network and internet communications.

Whether you followed the instructions in [Step 1: Setting up Your Environment](/relay/start/prep) or want to install the anon software directly using our provided methods, continue reading..

***

## Debian and Ubuntu

> *"I am running a Debian based Operating System and want to install the anon binary!"*

<div align="left"><figure><img src="/files/fu44FKlnRb2PNbk2oO1c" alt="" width="375"><figcaption></figcaption></figure></div>

#### To kickstart the installation process, execute the following command in your terminal or visit our [APT Repository instructions](/relay/start/install-anon-on-linux/apt) for a more hands-on experience:

{% code title="Copy ->" overflow="wrap" fullWidth="false" %}

```bash
sudo /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/anyone-protocol/anon-install/refs/heads/main/install.sh)"
```

{% endcode %}

This command initiates the download and execution of the installation script directly from our GitHub repository. Throughout the installation, you'll be prompted to provide necessary configurations for setting up the Anon Relay on your system, ensuring a tailored and secure deployment.&#x20;

{% hint style="info" %}
You can restart the script at any time to reconfigure the relay if you made a mistake during the process or want to change anything.
{% endhint %}

Upon successful installation, you'll receive a congratulatory message, indicating that the Anon Relay has been installed and configured successfully.

{% hint style="success" %}

```
==================================================
               Congratulations!
   Anon configuration completed successfully.
            https://docs.anyone.io
==================================================
```

{% endhint %}

To make sure the Relay is reachable, refer to: [Confirm ORPort Reachability](/relay/troubleshooting/orport) for instructions.

***

### **Anon Relay Configuration Wizard**

During the installation you will be prompted to read and accept the [Terms and Conditions](https://anyone.io/terms).

{% hint style="info" %}

```
Please read the terms and conditions at https://www.anyone.io/terms
Do you accept the terms and conditions? [yes/no] yes
```

{% endhint %}

#### The installation script will guide you through a step-by-step configuration process.

Allowing you to configure the following:

<details>

<summary>1. <mark style="color:blue;">Nickname</mark> and <mark style="color:blue;">ContactInfo</mark><br><em>Enter the desired Nickname and Contact information for your Anon Relay.</em></summary>

**Example:**

```
- Enter the desired Nickname and Contact information for your Anon Relay
1/7 Nickname (1-19 characters, only [a-zA-Z0-9] and no spaces): nickname
1/7 Contact Information (leave empty to skip): 
```

*Sources:* [*Nickname*](/sdk/native-sdk/manual#nickname-name) *and* [*ContactInfo*](/sdk/native-sdk/manual#contactinfo-email_address)

</details>

<details>

<summary><strong>2. </strong><mark style="color:blue;"><strong>MyFamily</strong></mark><strong> setup (Optional)</strong><br><em>If you're setting up more than one relay, fingerprints have to be specified in MyFamily.</em> </summary>

**Example:**

```
- Enter a comma-separated list of fingerprints for your relay's family
2/7 MyFamily fingerprints (leave empty to skip): AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA,BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
```

*Source:* [*MyFamily*](/sdk/native-sdk/manual#myfamily-fingerprint-fingerprint)

</details>

<details>

<summary><strong>3. </strong><mark style="color:blue;"><strong>BandwidthRate</strong></mark><strong> and</strong> <mark style="color:blue;">BandwidthBurst</mark> <strong>(Optional)</strong><br><em><strong>Enter a number in</strong> Mbit <strong>i</strong>f you want to specify a bandwidth rate and burst.</em></summary>

**Example:**

```
- Enter BandwidthRate and BandwidthBurst in Mbit (e.g., 100 for 100 Mbit)
3/7 BandwidthRate (leave empty to skip): 100
3/7 BandwidthBurst (leave empty to skip): 120
```

*Sources:* [*BandwidthRate*](/sdk/native-sdk/manual#bandwidthrate-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1) *and* [*BandwidthBurst*](/sdk/native-sdk/manual#bandwidthburst-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1)

</details>

<details>

<summary>4. Customise <mark style="color:blue;"><strong>ORPort</strong></mark><strong> (Optional)</strong><br><em>Specify a custom OR port if you don't want to use the default port <code>9001</code>.</em></summary>

**Example:**

```
- Enter ORPort
4/7 ORPort [Default: 9001]: 9004
ORPort set to: 9004
```

*Source:* [*ORPort*](/sdk/native-sdk/manual#orport-address-port-or-auto-flags)

</details>

<details>

<summary>5. <mark style="color:blue;">Ethereum Wallet</mark> Configuration (Optional)<br><em>Provide an Ethereum EVM address to register for contribution rewards.</em></summary>

**Example**

```
- Do you want to enter an Ethereum EVM address for contribution rewards
5/7 (yes/no): yes
5/7 Enter your Ethereum wallet address: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
```

*Source:* [*Rewards Program Registration*](/dashboard/register)

</details>

<details>

<summary>6. Disable or Enable the <mark style="color:blue;">Controlport</mark> (Optional)<br><em>Choose if you want the Controlport to be enabled on port <code>9051</code>. [Default: no]</em></summary>

**Example:**

```
- Should the anon.service ControlPort be enabled?
6/7 Enable ControlPort? [Default: no]: yes
```

*Source:* [*Controlport*](/sdk/native-sdk/manual#controlport-address-port-or-unix-path-or-auto-flags)

*Hint: It's necessary to enable this (yes) if you want to monitor your Relay through the ControlPort.*\
\
*See* [*Additional monitoring...*](/relay/start/install-anon-on-linux#monitor-anon-service-log)

</details>

<details>

<summary><strong>7.</strong> <mark style="color:green;">*<strong>UncomplicatedFirewall</strong></mark><strong> installation (Optional)</strong><br><em>Select if you want to install 'UFW' and explicitly allow the necessary ports for operation.</em></summary>

**Example**

```
- Would you like to install UncomplicatedFirewall and allow incoming traffic on:
- ORPort 9004
- SSH port 22

7/7 Configure and enable ufw (yes/no): yes
```

*External sources:* [*Ubuntu Wiki*](https://wiki.ubuntu.com/UncomplicatedFirewall) and [Ubuntu Community Documentation on UFW](https://help.ubuntu.com/community/UFW)

</details>

{% hint style="info" %}

#### Visit the Rewards Dashboard section to read more about how to sign up!

## [www.docs.anyone.io/rewards](/dashboard)

{% endhint %}

### Sources and Example

REPOSITORY:\
<https://github.com/anyone-protocol/anon-install>\
BASH SCRIPT:\
<https://github.com/anyone-protocol/anon-install/blob/main/install.sh>\
README:\
<https://github.com/anyone-protocol/anon-install/blob/main/README.md>

{% code title="Example from README" %}

```
...
Configuring anon
----------------

Please read the terms and conditions at https://www.anyone.io/terms

Do you accept the terms and conditions? [yes/no] yes

...

==================================================
           ANON Installation Complete
==================================================


                                                                 /$$
                                                                |__/
  /$$$$$$  /$$$$$$$  /$$   /$$  /$$$$$$  /$$$$$$$   /$$$$$$      /$$  /$$$$$$
 |____  $$| $$__  $$| $$  | $$ /$$__  $$| $$__  $$ /$$__  $$    | $$ /$$__  $$
  /$$$$$$$| $$  \ $$| $$  | $$| $$  \ $$| $$  \ $$| $$$$$$$$    | $$| $$  \ $$
 /$$__  $$| $$  | $$| $$  | $$| $$  | $$| $$  | $$| $$_____/    | $$| $$  | $$
|  $$$$$$$| $$  | $$|  $$$$$$$|  $$$$$$/| $$  | $$|  $$$$$$$ /$$| $$|  $$$$$$/
 \_______/|__/  |__/ \____  $$ \______/ |__/  |__/ \_______/|__/|__/ \______/
                     /$$  | $$
                    |  $$$$$$/
                     \______/


==================================================
        Start Relay Configuration Wizard
  (Or abort and manually edit /etc/anon/anonrc)
==================================================

- Enter the desired Nickname and Contact information for your Anon Relay
1/7 Nickname (1-19 characters, only [a-zA-Z0-9] and no spaces): nickname
1/7 Contact Information (leave empty to skip): 

- Enter a comma-separated list of fingerprints for your relay's family
2/7 MyFamily fingerprints (leave empty to skip): AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA,BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC

- Enter BandwidthRate and BandwidthBurst in Mbit (e.g., 100 for 100 Mbit)
3/7 BandwidthRate (leave empty to skip): 100
3/7 BandwidthBurst (leave empty to skip): 120

- Enter ORPort
4/7 ORPort [Default: 9001]: 9004
ORPort set to: 9004

==================================================
         Ethereum Wallet Configuration
==================================================

- Do you want to enter an Ethereum EVM address for contribution rewards?
5/7 Ethereum Address (yes/no): yes
5/7 Enter your Ethereum wallet address: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF

==================================================
       Enable Monitoring and Control port
==================================================

- Should the anon.service ControlPort be enabled?
6/7 Enable ControlPort? [Default: no]: yes

==================================================
      Optional Local Firewall Installation
==================================================

The default firewall configuration tool for Ubuntu is ufw.
Developed to ease iptables firewall configuration, ufw provides
a user friendly way to create an IPv4 or IPv6 host-based firewall.
By default UFW is disabled.

https://help.ubuntu.com/community/UFW


- Would you like to install UncomplicatedFirewall and allow incoming traffic on:
- ORPort 9004
- SSH port 22

7/7 Configure and enable ufw (yes/no): yes
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
The following NEW packages will be installed:
  ufw
...

Rules updated
Rules updated (v6)
Rules updated
Rules updated (v6)
Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
Firewall is active and enabled on system startup

==================================================
UFW installed and rules added for ORPort 9004 and SSH port 22.

Make sure old firewall rules are removed if they are no longer valid.
To show current UFW configuration: sudo ufw status
To remove an old rule: sudo ufw delete allow <port-number>

For improved security, consider setting up SSH key authentication.
Refer to official documentation: https://ssh.com/ssh/keygen for instructions.

Waiting for the fingerprint to be generated.
Please don't interrupt the process...

==================================================
              Anon Relay Fingerprint
     058B704D9EF0714C48125B733562657F3F471C08
==================================================

Nickname nickname
ContactInfo @anon: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Log notice file /var/log/anon/notices.log
ORPort 9004
ControlPort 9051
SocksPort 0
ExitRelay 0
IPv6Exit 0
ExitPolicy reject *:*
ExitPolicy reject6 *:*
BandwidthRate 100 Mbit
BandwidthBurst 120 Mbit
MyFamily AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA,BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC

==================================================
               Congratulations!
   Anon configuration completed successfully.
            https://docs.anyone.io
==================================================
```

{% endcode %}

***

## Maintenance and Monitoring

Additionally, you'll find some handy Linux Terminal commands for managing and maintaining your Anyone Relay instance. You can use [SSH for remote management](/relay/start/prep/ssh-setup) (Powershell) of the Linux Operating System and anon if you are on Windows. Otherwise use a regular SSH connection from another bash prompt or terminal window on on a remote machine.

### Check status for anon service

```bash
sudo systemctl status anon
```

### Start, stop and restart anon service

```sh
sudo systemctl start anon
sudo systemctl restart anon
sudo systemctl stop anon
```

### Update Anon to the latest version <a href="#update-anon-to-the-newest-version" id="update-anon-to-the-newest-version"></a>

Keep your Anyone Relay up-to-date with the latest enhancements and security patches by running

```bash
sudo apt-get update --yes
sudo apt-get install --only-upgrade anon --yes
```

### Monitor anon service log

Stay informed about the operation of your Anyone Relay by monitoring the service log with.

<pre class="language-bash"><code class="lang-bash"><strong>sudo tail -f /var/log/anon/notices.log
</strong></code></pre>

{% hint style="info" %}
Additional monitoring can be done with a third-party application called Nyx.\
[Read more about Nyx in our FAQ](/welcome/faq#how-to-install-nyx-for-monitoring-in-debian).
{% endhint %}

### Edit relay configuration

```bash
sudo nano /etc/anon/anonrc
```

### Verify relay configuration

```bash
sudo /usr/bin/anon -f /etc/anon/anonrc --verify-config
```

### Extra User Permissions

To simplify future operations and grant monitoring permissions, it's recommended to add your user to the '`debian-anon`' group. This eliminates the need for sudo privileges when running monitoring tools like [Nyx](/welcome/faq#how-to-install-nyx-for-monitoring-in-debian).&#x20;

```bash
sudo usermod -a -G debian-anon $USER
```


# Source

## Build from Source

Resources: <https://github.com/anyone-protocol/ator-protocol>

Please ensure you read and consider the configuration instructions before running this software.

#### Keys that CAN sign a release

The following keys are used to sign binary releases. One or many of these keys can sign the releases, do NOT expect them all:

* ID: 0xDC73B31AA1F797B180A87CBC7571AA42A0CBEFE9

You can also verify the binaries following this guide:

{% content-ref url="/pages/2nlToriqeL38TcWD5NZL" %}
[Binary verification](/relay/maintenance/binary-verification)
{% endcontent-ref %}

### Development

See the documentation in doc/HACKING/.

To build Anon Client from source:

```
./configure
make
make install
```

To build Anon Client from a freshly cloned git repository:

```
./autogen.sh
./configure
make
make install
```

Page last updated: 2025-06-22


# APT

## Supported platforms <a href="#supported-platforms" id="supported-platforms"></a>

| Platform | x86\_64 / amd64                                     | arm64                                               |
| -------- | --------------------------------------------------- | --------------------------------------------------- |
| Debian   | [✅](https://docs.docker.com/engine/install/debian/) | [✅](https://docs.docker.com/engine/install/debian/) |
| Ubuntu   | [✅](https://docs.docker.com/engine/install/ubuntu/) | [✅](https://docs.docker.com/engine/install/ubuntu/) |

### **Set up anon's** `apt` **repository:**

```sh
. /etc/os-release
sudo wget -qO- https://deb.en.anyone.tech/anon.asc | sudo tee /etc/apt/trusted.gpg.d/anon.asc
sudo echo "deb [signed-by=/etc/apt/trusted.gpg.d/anon.asc] https://deb.en.anyone.tech anon-live-$VERSION_CODENAME main" | sudo tee /etc/apt/sources.list.d/anon.list
```

### **Install the anon packages**

```sh
sudo apt-get update
sudo apt-get install anon
```

### **Default paths and files**

The Configuration file `/etc/anon/anonrc` is the primary file where the relay is configured based on your preference.  Go to the Anon Manual to read about all the available parameters, but keep in mind that some are still under development.&#x20;

{% hint style="warning" %}
Remember to add the [**MyFamily**](/sdk/native-sdk/manual#myfamily-fingerprint-fingerprint-1) parameter if you are operating more than one Relay.
{% endhint %}

#### Example anonrc

This is an example from a typical `anonrc` configuration for a middle Relay setup:

```sh
Log notice file /var/log/anon/notices.log
ORPort 9001
ControlPort 9051
ExitRelay 0
Nickname MyRelayNickname   # Between 1-19 characters, only [a-zA-Z0-9] and no spaces.
ContactInfo <me@ianon.who>
```

#### Anon Data Directory

The [Data Directory](/sdk/native-sdk/manual#datadirectory-dir) `/var/lib/anon/` contains the`keys` folder with the Identity Keys that generates the Relays fingerprint, backup or restore these keys to migrate a relays fingerprint.


# Docker

Docker Setup and Deployment

This instruction will guide you how to install a Relay in Docker for different Linux distributions. The instructions are applicable to both **amd64** and **arm64** architectures, including devices such as the Raspberry Pi.

### The latest Docker image can be found here:

<https://github.com/anyone-protocol/ator-protocol/pkgs/container/ator-protocol>

{% hint style="info" %}
From Anon version 0.4.9.7-live it is required to [accept terms and conditions](/relay/maintenance/updates#preseed-debconf-database) to run the client.
{% endhint %}

## Step by step installation

Type all the `commands` in a terminal window. Each code block can be pasted in full.

### 1.   Add Docker repository

{% tabs %}
{% tab title="Debian / Ubuntu" %}

```bash
sudo apt-get install ca-certificates curl gnupg -y 
sudo install -m 0755 -d /etc/apt/keyrings
. /etc/os-release
sudo curl -fsSL https://download.docker.com/linux/$ID/gpg | sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg
sudo chmod a+r /etc/apt/keyrings/docker.gpg
sudo echo \
  "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/$ID \
  $(. /etc/os-release && sudo echo "$VERSION_CODENAME") stable" | \
  sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
sudo apt-get update
```

{% endtab %}

{% tab title="Fedora" %}

```bash
sudo dnf -y install dnf-plugins-core
sudo dnf config-manager --add-repo https://download.docker.com/linux/fedora/docker-ce.repo -y
```

{% endtab %}
{% endtabs %}

### 2.   Install the Docker packages

{% tabs %}
{% tab title="Debian / Ubuntu" %}

```bash
sudo apt-get install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin -y
```

{% endtab %}

{% tab title="Fedora" %}

```bash
sudo dnf install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin -y
sudo systemctl enable --now docker
```

{% endtab %}
{% endtabs %}

### 3.   Prepare directories and fetch files

<pre class="language-bash"><code class="lang-bash">sudo mkdir /opt/compose-files/
sudo mkdir -p /opt/anon/etc/anon/
sudo mkdir -p /opt/anon/run/anon/
sudo mkdir -p /root/.nyx/
sudo chmod -R 700 /opt/anon/run/anon/
sudo chown -R 100:101 /opt/anon/run/anon/
sudo touch /opt/anon/etc/anon/notices.log
sudo chown 100:101 /opt/anon/etc/anon/notices.log
sudo useradd -M anond
sudo wget -O /opt/compose-files/relay.yaml https://raw.githubusercontent.com/anyone-protocol/anon-install/refs/heads/main/docker/anon-relay/relay.yaml
<strong>sudo wget -O /opt/anon/etc/anon/anonrc https://raw.githubusercontent.com/anyone-protocol/anon-install/refs/heads/main/docker/anon-relay/anonrc
</strong>sudo wget -O /root/.nyx/config https://raw.githubusercontent.com/anyone-protocol/anon-install/refs/heads/main/docker/anon-relay/config
</code></pre>

### 4.   Create and start the Docker container

```bash
sudo docker compose -f /opt/compose-files/relay.yaml up -d
```

#### Done!

***

## Commands for updating, testing and monitoring:

#### Edit relay configuration

```bash
sudo nano /opt/anon/etc/anon/anonrc
```

#### Update relay to run latest version

```bash
sudo docker container rm --force anon-relay
sudo docker pull ghcr.io/anyone-protocol/ator-protocol:latest-manual
sudo docker compose -f /opt/compose-files/relay.yaml up -d
```

#### Install Nyx monitor

{% tabs %}
{% tab title="Debian / Ubuntu" %}

```sh
sudo apt-get install nyx
```

{% endtab %}

{% tab title="Fedora" %}

```bash
sudo dnf install nyx
```

{% endtab %}
{% endtabs %}

#### Monitor relay with Nyx

```bash
sudo nyx -s /opt/anon/run/anon/control
```

#### Check status for containers

```bash
sudo docker ps
```

#### Start, stop and restart the relay container

```bash
sudo docker start anon-relay
sudo docker restart anon-relay
sudo docker stop anon-relay
```

#### Check systemctl logs for anon service

```bash
sudo docker logs anon-relay
```

#### Monitor anon log

```bash
sudo tail -f /opt/anon/etc/anon/notices.log
```

#### Remove the relay container

```bash
sudo docker rm anon-relay --force
```


# Relay Roles


# Exit Relay Configuration

This page instructs how to configure an Exit Relay with recommended minimum configuration.

This setup process includes installing the Anon client using the APT repository, configuring the client as an Exit, adding an Exit Notice, setting up firewall rules and guidelines on how to achieve Double-reverse DNS.

{% hint style="danger" %}
It is important to understand that running an Exit relay requires more maintenance and security awareness than in comparison to a Middle relay. Read our [Exit Guidelines](/relay/guidelines/exit-guidelines) before installing an Exit Relay. It is recommended to **never** host an Exit relay at home or other private premises.
{% endhint %}

### **Install using the** `apt` **repository**

```sh
. /etc/os-release
sudo wget -qO- https://deb.en.anyone.tech/anon.asc | sudo tee /etc/apt/trusted.gpg.d/anon.asc
sudo echo "deb [signed-by=/etc/apt/trusted.gpg.d/anon.asc] https://deb.en.anyone.tech anon-live-$VERSION_CODENAME main" | sudo tee /etc/apt/sources.list.d/anon.list
```

### Fully upgrade the system

```sh
sudo apt-get update
sudo apt-get upgrade
```

### Install anon

```sh
sudo apt-get install anon
```

### Configure anonrc

Edit the anon configuration:

{% code fullWidth="false" %}

```sh
sudo nano /etc/anon/anonrc
```

{% endcode %}

Use the template below and replace with a non-personal mail address for `ContactInfo` and change `Nickname` to your liking.

```
Nickname ExitRelayName
ContactInfo email@me.com
Log notice file /var/log/anon/notices.log
ORPort 9001
SocksPort 0
ExitRelay 1
IPv6Exit 0
DirPort 80
DirPortFrontPage /etc/anon/anyone-exit-notice.html
ReevaluateExitPolicy 1
ExitPolicy reject *:25
ExitPolicy reject *:587
ExitPolicy reject *:465
ExitPolicy reject *:2525
ExitPolicy reject *:3389
ExitPolicy reject *:23
ExitPolicy reject *:465
ExitPolicy reject *:3128
ExitPolicy reject *:5900
ExitPolicy reject *:9999
```

### Download the Anyone Exit Notice

```sh
sudo curl -o /etc/anon/anyone-exit-notice.html -fsSLO https://raw.githubusercontent.com/anyone-protocol/anon-install/refs/heads/main/html/anyone-exit-notice.html
```

### Add a non-personal mail address to the Exit Notice

Edit line 101 in the file `anyone-exit-notice.html` and change the value `EMAIL_ADDRESS` to a non-personal mail address to be able to respond to Abuse complaints.

```sh
sudo nano +101 /etc/anon/anyone-exit-notice.html
```

### Restart anon service to apply anon configuration

```sh
sudo systemctl restart anon
```

If additional changes are made to the `anyone-exit-notice.html` file, reloading the anon service to apply the changes is necessary. Reloading is executed with the command:

```sh
sudo systemctl reload anon
```

### Apply firewall rules

This example assumes default ports are used for ORPort (`9001`), SSH (`22`) and HTTP (`80`). Change these values from the example if needed.

```sh
sudo apt-get install ufw
sudo ufw allow 9001
sudo ufw allow 80
sudo ufw limit 22
sudo ufw enable
```

### Double-reverse DNS

It is **highly recommended** that you set up a valid Double-reverse DNS, also known as a "double reverse lookup", which refers to the process of performing a reverse DNS lookup on the result of a forward DNS lookup. This is typically done for purposes of adding legitimacy to the identity of a remote system. To achieve this the two DNS records, **PTR** and **A,** need to be configured for an IP-address.

{% hint style="info" %}

* **Pointer Record (PTR)**: Also called **Reverse DNS** is a DNS record that maps an IP address to a domain name, commonly used for reverse DNS lookups to verify the authenticity of the sender's domain. PTR adds another layer of legitimacy when accessing services and for the destination to easier evaluate the source.
* **Address Record (A):** The most commonly used DNS record that links a domain name to an IP address, enabling devices to find and connect to websites and servers on the internet.
  {% endhint %}

For example, if you have a domain name like `example.com` with an IP address of 192.0.2.1, a double-reverse DNS lookup would involve:

**Pointer Record (PTR)**

```
Reverse lookup: Resolving 195.1.2.3 to example.com.
```

**Address  Record (A)**

```
Forward lookup: Resolving example.com to 195.1.2.3.
```

### How do I achieve Double-reverse DNS?

As mentioned above the two DNS records that need to be configured are **A** and **PTR**. For the exact steps on how to configure the two DNS records then it is important to refer to the providers documentation on how to achieve this.

Mind that multiple Exit IP-addresses must **not** have identical DNS records, so adding an index number per Exit, like `anyone-exit-1.example.com` is a suggestion.

**Pointer Record (PTR)**

In the example where an Exit Relay is hosted at a cloud provider, then the control panel of the VPS will provide the possibility to configure a PTR record for your Exit IP. This setting can also be referred to as Reverse DNS, rDNS, Reverse mapping and more.

#### Address Record (A)

**Here's a simplified breakdown:**

1. **Acquire a domain name:** Choose a domain registrar (e.g., GoDaddy, Namecheap). Search for a domain name and purchase it.
2. **Manage DNS Settings:** Log in to your domain registrar's account. Go to the DNS management section.
3. **Create an A Record:** Add a new A record for your domain. Set the Hostname (e.g., `anyone-exit-1.example.com`). Enter the Public IP address of your Exit relay and save the record. <br>

{% hint style="warning" %}
DNS changes can take between 24 and 48 hours to fully propagate across the internet. However, it can sometimes be much quicker for simple DNS changes, or longer, especially for complex DNS configurations or in specific regions.
{% endhint %}


# Anon Options

See all anon options on the Manual page.

{% content-ref url="/pages/u2rzmJTz21NEQcXIkJ4b" %}
[Manual](/sdk/native-sdk/manual)
{% endcontent-ref %}


# Multi-mining with Taofu TPN

This page will guide you through the procedure to setup multi-mining by installing a Anyone Relay with a Tao TPN worker in parallel. This installation is a fork of [https://github.com/taofu-labs/tpn-subnet](https://github.com/taofu-labs/tpn-subnet/), you can read more about mining with Taofu TPN at [https://www.taofu.xyz](https://www.taofu.xyz/).

1. Clone the repo

{% code fullWidth="false" %}

```bash
cd ~
git clone https://github.com/rA3ka/tpn-subnet
cd tpn-subnet
```

{% endcode %}

2. Edit the `anonrc` configuration in the file docker-compose.yml and replace `ContactInfo` and `Nickname` with your own.

```bash
nano ~/tpn-subnet/federated-container/docker-compose.yml
```

3. Run the TPN install script to set install a worker. Follow the install procedure and input the requested values.

```bash
bash ~/tpn-subnet/refs/heads/main/scripts/install_worker.sh
```


# Network & Firewall

{% content-ref url="/pages/352O1wCzbYjlXzDmReKT" %}
[Router Port Forwarding](/relay/network/port-forward)
{% endcontent-ref %}

{% content-ref url="/pages/LEvkDQVUc3vmtrzRP0fu" %}
[Firewall Setup & Rules](/relay/network/firewall)
{% endcontent-ref %}

{% content-ref url="/pages/c5stPAkM8bbN3a0aNtJH" %}
[Configure IPv4 and IPv6](/relay/network/configure-ipv4-and-ipv6)
{% endcontent-ref %}

{% content-ref url="/pages/7kpKoQ93vF7PNz6Hlu1o" %}
[SOCKS Proxy Setup](/relay/network/socks)
{% endcontent-ref %}


# Router Port Forwarding

Port forwarding is a necessary step in setting up a Anyone Relay, allowing external connections to reach your relay's designated port (default: 9001). This universal guide covers the port forwarding process applicable to most routers. It's important to note that while the default port is 9001, you can optionally choose another port.

### 1.   Access Your Router's Settings

In this step we provide examples for different Operating System's on how to get your routers IP-address to access its settings. The IP-address of a router may differ but is typically something like: `192.168.x.x` or `10.x.x.x`.

**If you already know how to access your router's settings then you can skip to** [**next step**](#id-2.-locate-the-port-forwarding-section-in-your-routers-control-panel)**.**

{% tabs %}
{% tab title="Windows" %}

1. **Open Command Prompt**

Press `Win + R`, type `cmd`, and press Enter to open the Command Prompt.

2. **Run `ipconfig`**

Type `ipconfig` and press Enter. Look for the "Default Gateway" entry under the active network connection.

**Identify Router IP**

```
Default Gateway . . . . . . . . . : 192.168.1.1
```

{% endtab %}

{% tab title="macOS" %}

1. **Search for and open the 'terminal.app' application.**
2. **Copy and paste the below commands in full in the terminal.**

{% code fullWidth="false" %}

```sh
route -n get 'default' | grep 'gateway'
```

{% endcode %}

<div align="left"><figure><img src="/files/CRkzgdfbBGvKzsfPCtA9" alt=""><figcaption></figcaption></figure></div>

In this example, the output of the commands show that the IP-address of the router is **`10.211.57.1`**. This is the IP-address to open a browser to access router settings.
{% endtab %}

{% tab title="Linux" %}

1. **Search for and open the 'terminal' application.**
2. **Copy and paste the below commands in full in the terminal.**

```sh
ip route | grep default | cut -d " " -f1-3
```

<div align="left"><figure><img src="/files/zkDIRDvvoIOJKPDMBQl7" alt=""><figcaption></figcaption></figure></div>

In this example, the output of the commands show that the IP-address of the router is **`10.211.56.1`**. This is the IP-address to open a browser to access router settings.
{% endtab %}
{% endtabs %}

### **Open Your Web Browser**

Now open any web browser and paste the IP-address of the router that you looked up in the previous step.

#### **Login to the Router**

Enter your router's username and password. If you haven't changed these, check your router documentation or on the back label, for default credentials.

### 2.   Locate the Port Forwarding Section in your Routers Control Panel

#### **Navigate to Port Forwarding**

Look for a section named "**Port Forwarding**" in your router settings. The location may vary but is often found under the "Advanced" or "Security" tab.

#### **Choose a Device**

Select the device running your Anyone Relay from the list of connected devices.

### 3. Configure Port Forwarding

**a.   Add a New Rule**\
Create a new port forwarding rule.\
\
b.   **Specify Port**\
Enter the port number \
Default is normally 9001 otherwise specify your chosen port in the required fields.\
\
c.   **Select Protocol**\
Choose "TCP/UDP" as the protocol.\
\
d.   **Set IP Address**\
Enter the local IP address of your Anyone Relay device. You can find this in your device's network settings.\
\
e.   **Leave source IP empty**\
Do not enter anything in the field for source IP to ensure anyone on the network can connect to your relay on the specified port.

#### Save your settings, and if required, reboot your network router or firewall.

### 4.   Verify Port Forwarding

#### **Use Online Tools**

Utilize online tools like "CanYouSeeMe.org" to check if your specified port is open.

Make sure your Anyone Relay is configured to use the forwarded port. \
Update the anonrc file with the chosen port accordingly.

```bash
ORPort <YourChosenPort>
```

### 5.   Security Considerations

#### **Use Strong Passwords**

Make sure your router login credentials and Anyone Relay are secured with strong, unique passwords.

\
**Regularly Monitor Activity**

Periodically check router logs for any unauthorized access and monitor your relay's performance.

***

### External Resources

For router-specific instructions or troubleshooting, refer to your router's manual or visit the manufacturer's website. Below are links to guides for some popular router brands:

* [Linksys Port Forwarding Guide](https://www.linksys.com/support-article?articleNum=138535)
* [Netgear Port Forwarding Guide](https://kb.netgear.com/24289/How-do-I-set-up-port-forwarding-to-a-local-server-on-my-NETGEAR-router)
* [TP-Link Port Forwarding Guide](https://www.tp-link.com/us/support/faq/1379/)
* [D-Link Port Forwarding Guide](https://www2.dlink.com/us/en/support/faq/routers/mydlink-routers/dir-605l/how-do-i-configure-port-forwarding-on-my-router)
* [Asus Port Forwarding Guide](https://www.asus.com/support/FAQ/1037906/)

Remember that the steps may vary slightly based on different router models. Always prioritize security and consult your router's documentation for model-specific details.


# Firewall Setup & Rules

This instruction guides you how to setup up firewall in Debian and Ubuntu using Anon ORPort 9001 and SSH port 22 as an example.

### 1. Update sources and install

Update your system and install the package and dependencies using these commands

{% tabs %}
{% tab title="Debian / Ubuntu" %}

```bash
sudo apt-get update -y
sudo apt-get install ufw -y
```

{% endtab %}
{% endtabs %}

### 2. Enable firewall and add allow rules for SSH and ORport

{% tabs %}
{% tab title="Debian / Ubuntu" %}

```bash
sudo ufw allow 22
sudo ufw allow 9001
sudo ufw enable
```

When prompted with the message '`Command may disrupt existing ssh connections'`, type '**y**' and hit **ENTER**.
{% endtab %}
{% endtabs %}


# Configure IPv4 and IPv6

### Understanding IPv4 and IPv6

IPv4 is the traditional Internet Protocol version characterized by a limited address space. Many networks still heavily rely on IPv4.

IPv6 presents a significantly expanded address space, designed to accommodate the ever-growing number of devices connected to the internet.

By default, IPv6 is enabled for the relay service and can be disabled if necessary. Some ISPs do not provide IPv6 for their internet services, and in such cases, disabling IPv6 is not mandatory as it does not cause any issues. Disabling IPv6 suppresses log messages like:

```
[notice] Unable to find IPv6 address for ORPort 9001. You might want to specify IPv4Only to it or set an explicit address or set Address.
```

### Configuring IPv4 & IPv6 for Your Relay

**IPv4 Configuration with IPv6 Enabled:** Edit the anonrc file and specify the IPv4 address for the ORPort.

```bash
ORPort <YourChosenPort>
```

**IPv4 Configuration with IPv6 Disabled (Optional):** Disable IPv6 on your network and update the anonrc file accordingly.

```bash
ORPort <YourChosenPort> IPv4Only
AddressDisableIPv6
```

Save the changes and restart the service.


# SOCKS Proxy Setup

To set up a SOCKS5 Proxy on your local relay to allow LAN traffic to pass through the Anyone network, follow this example:

## Overview

A SOCKS proxy in an onion network, like **Anyone**, serves as an intermediary that routes traffic through multiple layers of encryption, ensuring anonymity. When using a SOCKS proxy with **Anyone**, your internet traffic is first directed to the proxy, which then forwards it into the **Anyone** **Network**. The data is encrypted and passed through several relay nodes, with each node only knowing the previous and next hop, but not the entire route. This layered approach prevents any single point from knowing both the origin and destination of the traffic, enhancing privacy and security for users who wish to remain anonymous online.

<div align="left"><figure><img src="/files/tIQpV3MQXRtUqHObOcl7" alt="" width="375"><figcaption></figcaption></figure></div>

## Configuration Steps

1. **Set Up the SOCKS5 Proxy**
   * Configure your relay to behave as a SOCKS5 proxy by editing the anon configuration file. This will enable it to route traffic from your LAN devices through the **Anyone** **Network**, ensuring anonymity. See steps below for [Standalone installation](#edit-the-anon-configuration), for the Anyone Router Hardware, go to [Control Panel Walkthrough](/hardware/setup-guides/controlpanel#proxy-settings-beta)
2. **Specify Relay IP and SOCKS Port**
   * Once your relay is configured as a proxy, specify its IP address and the SOCKS port on any device within your LAN that you want to route through the **Anyone** **Network**.
3. **Match LAN Subnet**
   * Remember to change the IP subnet to match the subnet of the Local Area Network (LAN) that you want to allow to use the proxy. This ensures that all traffic is properly routed through the **Anyone** **Network**.

{% hint style="warning" %}
**Disclaimer:**

This configuration should be considered experimental. \
Stability and security can not be guaranteed.
{% endhint %}

## Edit the anon configuration

Use 'nano' to edit the [anonrc](/sdk/native-sdk/manual#f-anonrc-file-file) file in Ubuntu.

```sh
sudo nano /etc/anon/anonrc
```

### Add SocksPort and SocksPolicy to the Anon Configuration

This configuration will allow all clients on the subnet `192.168.1.0/24` to connect through the proxy. Please note that the **LAN IP** of the Relay is assumed to be `192.168.1.10`. However, the **LAN IP** of the Relay and subnet may vary for different networks and routers.

***Sources**:* [*SocksPort*](/sdk/native-sdk/manual#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) *and* [*SocksPolicy*](/sdk/native-sdk/manual#sockspolicy-policy-policy)

```sh
SocksPort 192.168.1.10:9050
SocksPolicy accept 192.168.1.0/24
```

### Proxy Settings: Linux / macOS / Windows

{% content-ref url="/pages/FF3XWni6VUKhyXkecIYM" %}
[Connect to Anyone](/connect)
{% endcontent-ref %}

### Anyone Relay hardware Proxy Settings

To learn how to enable Proxy servers on the Anyone Relay hardware, go to [Control Panel Walkthrough](/hardware/setup-guides/controlpanel#proxy-settings-beta)


# Updates & Maintenance

{% content-ref url="/pages/lDYTiyU0sU6fRBYh4Cb3" %}
[System & Anon Updates](/relay/maintenance/updates)
{% endcontent-ref %}

{% content-ref url="/pages/2nlToriqeL38TcWD5NZL" %}
[Binary verification](/relay/maintenance/binary-verification)
{% endcontent-ref %}


# System & Anon Updates

This page helps you with updating the Anon binary and accepting the terms and conditions.

When installing or upgrading the Anon package to version anon-0.4.9.7 and above, necessary steps to agree to the [Terms and Conditions](https://www.anyone.io/terms) must be applied, for these operations to succeed successfully. We offer different methods to accept the agreement, either manually or in advance.

### Using APT package manager

Update list of available packages

```shell
sudo apt-get update
```

Upgrade to the latest Anon package.

```sh
sudo apt-get --only-upgrade install anon
```

Accept the terms and conditions by highlighting `<Yes>` and hit **Enter**.

<figure><img src="/files/Xn1Ov1pjMyoNdAJjmjNZ" alt="" width="563"><figcaption></figcaption></figure>

***

### How to accept the Terms and Conditions prior to installing or upgrading the Anon binary.

#### Preseed debconf database

Apply the debconf preseed:

```bash
sudo echo "anon anon/terms boolean true" | debconf-set-selections
```

Verify that the debconf preseed has applied properly:

```bash
sudo debconf-show anon
```

***

### Agree to terms and conditions with a parameter in anonrc

Add the parameter `AgreeToTerms 1` in the **anonrc** file, normally located `/etc/anon/anonrc`.&#x20;

***

### Ansible playbook

Add the configuration to your playbook:

{% code title="playbook.yaml" %}

```yaml
- name: Accept terms and conditions
  ansible.builtin.debconf:
    name: anon
    question: anon/terms
    value: "true"
    vtype: select
```

{% endcode %}


# Binary verification

How to verify that your Anyone command-line software is safe to use  (security best-practice)

Verifying the integrity and authenticity of downloaded software is a critical security step.\\

\
This page explains how to confirm that the files you're downloading are created and signed by the official Anyone team and have not been modified in transit.

Every ANON release is cryptographically signed using a trusted GPG key.&#x20;\
These signatures allow you to independently verify that the files you're about to use match what the developers intended to publish, free from tampering, corruption, or third-party interference.

{% hint style="success" %}
This guide works for Windows, Mac or Linux.
{% endhint %}

## Table of Contents:

The steps to verify the anon binaries are advanced but easy to follow:

* [Installing the required tools (such as GPG)](#installing-gnupg)
* [Importing the official Anyone signing key](#verify-and-import-the-signing-key)
* [Verifying release signatures](#verify-release-signatures)
* [Verifying package files](#verifying-package-files)
* [Verifying binaries](#binary-verification)

***

## Installing GnuPG

### Windows

Gpg4win\
<https://gpg4win.org/download.html>

### Mac

GPGTools\
[https://gpgtools.org](https://gpgtools.org/).

### Linux (Debian/Ubuntu)

```bash
sudo apt-get install gnupg
```

{% hint style="info" %}
GnuPG is normally installed by default on most Linux operating systems
{% endhint %}

## Verify and Import the Signing Key

To get the official signing key, download it from the Anyone Repository, check if it's the [correct key ID](https://github.com/anyone-protocol/ator-protocol?tab=readme-ov-file#keys-that-can-sign-a-release) published on Anyone Protocol GitHub page and import it to [GnuPG](https://www.gnupg.org/).

### Download the Signing Key

On Windows or Mac, download the signing key from the Anyone repository.

<https://deb.en.anyone.tech/anon.asc>

{% hint style="info" %}
With some browsers you can view and save the contents of the key file manually using:\
`view-source:https://deb.en.anyone.tech/anon.asc`
{% endhint %}

On Linux download it with Wget:

```bash
wget https://deb.en.anyone.tech/anon.asc
```

### Verify the Signing Key

Check the key ID of the signing key using a terminal window:

```bash
gpg anon.asc
```

{% hint style="info" %}
The ID is published on the official [GitHub repository for the Anyone Protocol](https://github.com/anyone-protocol/ator-protocol?tab=readme-ov-file#keys-that-can-sign-a-release):
{% endhint %}

{% hint style="success" %}
If the ID is a match, then you can continue importing the key to your keychain.
{% endhint %}

{% hint style="danger" %}
If the ID **does not** match, delete the "anon.asc" file and [download the correct signing key](#download-the-signing-key).
{% endhint %}

### Import the Signing Key

```bash
gpg --import anon.asc
```

## Verify Release Signatures

In this example we will use the the `Release` and `Release.gpg` files from the `../dists/anon-live-bookworm` directory to verify the repository.&#x20;

### Download the necessary files from the repo

```bash
wget https://deb.en.anyone.tech/dists/anon-live-bookworm/Release
```

```bash
wget https://deb.en.anyone.tech/dists/anon-live-bookworm/Release.gpg
```

### Verify the Release Signature

```bash
gpg --verify Release.gpg Release
```

{% hint style="success" %}
If the signature is valid and matches the imported key, you'll see:\
gpg: Good signature from "Anon Packages <contact@ator.io>"
{% endhint %}

### Verify with InRelease

To combine the two steps above verify using the `InRelease` file.&#x20;

```bash
wget https://deb.en.anyone.tech/dists/anon-live-bookworm/InRelease
gpg --verify InRelease
```

This checks the inline GPG signature against the contents of the file. It does the same thing as verifying `Release.gpg` with `Release`, just in one file.

## Verifying Package Files

After confirming that the metadata is signed and valid, you can now proceed to verify the packages.

### Inspect Release Checksums

To view and inspect package checksums open the `Release` file in a text editor on Windows or with the terminal if you are using Linux or Mac:

```bash
less Release
```

You'll see some details about the release:

```
Origin: Anon
Label: Anon
Codename: anon-live-bookworm
Date: Wed, 23 Apr 2025 09:25:31 UTC
Architectures: amd64 arm64
Components: main
Description: Anon Debian Boookworm Live

```

And checksum entries like:

```
MD5Sum:
 517f33fcdd0c3457d07ade7377c69481 4317 main/binary-amd64/Packages
 faad00dfd4ba531d4943ad24ac05f92d 2142 main/binary-amd64/Packages.gz
...
SHA1:
 4b57931202694b5bffb83eac2e26ac2d05553a6b 4317 main/binary-amd64/Packages
 9346467ecd5191d547f981c9a0a84f62abef1fdb 2142 main/binary-amd64/Packages.gz
...
SHA256:
 54a0a77a37a43a958d928ac18ffe4801206dcb267f14bfcaa0fe74018a159990 4317 main/binary-amd64/Packages
 f4642972c01ab1cab6e9940b8e4cdd37620eb754e5810e558fb0dff57dd9a8c3 2142 main/binary-amd64/Packages.gz
...
SHA512:
 2228e674d09dba931500acf52b93db896cfcc33453e98c82624c22e4f0e4eaeaf708c3c047e418827d55b8a597b7ed53fba2f00b71843f738207d66acee573e9 4317 main/binary-amd64/Packages
 ce6049932b4190d840c9d4aa5cb12ff0c9a4527b26b5363178c59dd4dd470347871faa03d0cbf847f3daf7a3c499a134074181d79c7eeb0f0212e209cf2b937c 2142 main/binary-amd64/Packages.gz
```

These checksums are used to verify the actual contents of the `Packages` files and package binaries.

### Download the Packages file

#### For Windows use the direct link: <https://deb.en.anyone.tech/dists/anon-live-bookworm/main/binary-amd64/Packages>

#### For Linux and Mac

Download the file compressed

```bash
wget https://deb.en.anyone.tech/dists/anon-live-bookworm/main/binary-amd64/Packages.gz
```

```
gunzip Packages.gz
```

Or download the file uncompressed

```bash
wget https://deb.en.anyone.tech/dists/anon-live-bookworm/main/binary-amd64/Packages
```

Search for the Binary in the `Packages` file

```bash
grep -A 5 'pool/main/a/anon/anon_' Packages
```

You'll get the following or similar output, it's different for each binary:

```
Filename: pool/main/a/anon/anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb
Size: 2137752
SHA512: 700513e638268e9fc84e9c7ad5e4e4fb4764fd27d9e4c81465bd19b1d96ef48bd21cf195fc26e945d7dc28d8ea26d2c3a678028a2b751134d719207b4901d092
SHA256: d2ce6070d1cf083458bb5dfb7903f5db327c6b932652da24f280e6ed205dcc5d
SHA1: a9834617b19fffc47c5449dab99126d5429cd1c4
MD5sum: 8880097147b595680511a0ddd29d7405
```

## Binary Verification

### Binary Verification on Linux or Mac

Download the Anon Binary\
<https://deb.en.anyone.tech/pool/main/a/anon/anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb>

```bash
wget https://deb.en.anyone.tech/pool/main/a/anon/anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb
```

Use `sha256sum` to check the SHA256 of the file

```
sha256sum anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb
```

You'll get the following or similar output, it's different for each binary:

```
d2ce6070d1cf083458bb5dfb7903f5db327c6b932652da24f280e6ed205dcc5d  anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb
```

{% hint style="success" %}
Confirm that the SHA256 hash matches what’s listed for the deb file in `Packages`
{% endhint %}

{% hint style="danger" %}
If a hash does not match, delete the binary and return to [Download the Anon Binary](#download-the-anon-binary).
{% endhint %}

### Binary Verification on Windows

For this example we will verify the same .deb file as before. To find Windows executable, see [GitHub Releases](https://github.com/anyone-protocol/ator-protocol/releases).&#x20;

Download the Anon bookworm Binary\
<https://deb.en.anyone.tech/pool/main/a/anon/anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb>

From a Command Prompt or PowerShell, check the SHA256 hash of the downloaded binary.&#x20;

```powershell
certutil -hashfile sha256sum anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb SHA256
```

You'll get the following or similar output, it's different for each binary:

```
SHA256 hash of .\anon_0.4.9.11-live-1~d12.bookworm+1_amd64.deb:
d2ce6070d1cf083458bb5dfb7903f5db327c6b932652da24f280e6ed205dcc5d
CertUtil: -hashfile command completed successfully.
```

{% hint style="success" %}
Confirm that the SHA256 hash matches what’s listed for the deb file in `Packages`
{% endhint %}

{% hint style="danger" %}
If a hash does not match, delete the binary and return to [Download the Anon Binary](#download-the-anon-binary).
{% endhint %}


# Unattended Upgrades

Automatically keep your entire system up to date.

This configuration will enable your entire system to upgrade itself to always keep it up to date and perform automatic reboots if required.

1. `sudo apt-get install unattended-upgrades`
2. Add below to `/etc/apt/apt.conf.d/50unattended-upgrades`:

```bash
Unattended-Upgrade::Origins-Pattern {
    "origin=Debian,archive={{ ansible_distribution_release }}";
    "origin=Debian,archive={{ ansible_distribution_release }}-security";
    "origin=Debian,archive={{ ansible_distribution_release }}-updates";
    "origin=Debian,archive=stable-backports";
    "origin=Anon";
};
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
```

3. Add below to `/etc/apt/apt.conf.d/20auto-upgrades`:

```bash
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";
APT::Periodic::Unattended-Upgrade "1"
```

4. `sudo systemctl restart unattended-upgrades`


# Troubleshooting

{% content-ref url="/pages/LaNOUyRoVOjab4UxRMND" %}
[CGNAT & IPv4 reachability](/relay/troubleshooting/reachability)
{% endcontent-ref %}

{% content-ref url="/pages/p8fWOVflHfLDaOrR2gdF" %}
[OR Port Check](/relay/troubleshooting/orport)
{% endcontent-ref %}

{% content-ref url="/pages/6ss4ML1lGmojTWN7yz3k" %}
[DoS mitigation tips](/relay/troubleshooting/dos-mitigation)
{% endcontent-ref %}


# CGNAT & IPv4 reachability

### What is CGNAT?

Carrier-Grade Network Address Translation (CGNAT) is a technique used by Internet Service Providers (ISPs) to deal with the shortage of available IPv4 addresses. In a CGNAT environment, multiple customers share a single public IPv4 address, hindering the ability to directly forward ports to devices within a network.

### Diagnosing CGNAT

#### **Check Your Router's WAN IP:**

* Log in to your router and locate the **WAN IP** address. If it's a private IP address (e.g., 10.x.x.x, 100.x.x.x, 192.168.x.x,), your network is likely behind a CGNAT.
* Check if your routers **WAN IP** matches the **IP address** on [browserleaks.com/ip](https://browserleaks.com/ip), if the IP's does not match then you can be certain CGNat is enabled for your Internet service.

**Check with Your ISP:**

* Contact your Internet Service Provider and inquire about your IP address type. If they confirm it's a private IP, you're likely under CGNAT.

### Dealing with CGNAT

**Contacting Your ISP Requesting a Dynamic Public IP:**

* Inform your ISP about the port forwarding needs.
* Request a dynamic public IP address to enable you to forward ports.
* Some ISP's charge extra for a static IP if the ISP can't help you with a dynamic IP.


# OR Port Check

This page provides guidance on confirming the reachability of the ORPort (Onion Router Port), a vital element in network communication.

The ORPort is where a relay listens for incoming connections. The ORPort self-test is a verification process for its reachability and functionality. A successful test, denoted by a green log message, confirms proper operation. However, a yellow or red log message suggests a potential issue with configuration or network connectivity.

### Install Nyx

```bash
sudo apt-get install nyx --yes
```

### Open Nyx

<pre class="language-bash" data-full-width="false"><code class="lang-bash"><strong>sudo nyx
</strong></code></pre>

**ORPort Reachability** typically confirms within a minute when functioning correctly. A green-marked log message confirms the successful operation of the relay. No further action is needed as the relay is now reachable from the internet.

<div align="left"><figure><img src="/files/stGmSdFamRIpH2ozAfGE" alt="" width="375"><figcaption><p>Self-testing indicates your ORPort &#x3C;public IP> is reachable from the outside.</p></figcaption></figure></div>

A WARN log message (marked in red rectangle below) signals an issue, indicating that the relay is not operating successfully. The two most common issues are:

1. **Port Forward Configuration:**
   * [The port forward configuration](/relay/network/port-forward) is either missing or incorrectly set up in your router.
2. **CGNAT Enabled by ISP:**
   * Your router may lack its own public IPv4 address, as your Internet Service Provider (ISP) has enabled [Carrier-Grade Network Address Translation (CGNAT)](/relay/troubleshooting/reachability) for your internet service.

<div align="left"><figure><img src="/files/4QSmqtDfijlzW1OlU06v" alt="" width="375"><figcaption><p>Your server has not managed to confirm reachability..</p></figcaption></figure></div>


# DoS mitigation tips

Denial-of-Service (DoS) Protection

Anyone relays, especially exit and directory relays, are vulnerable to DoS attacks that can degrade performance or disrupt services. Anon provides built-in DoS mitigation options to protect relays from excessive circuit creation, connection flooding, or stream abuse. \
\
Below are some parameters that can be configured in your `anonrc` file for enhanced protection.

### :small\_blue\_diamond:Circuit Creation DoS Protection

Protects your relay from excessive circuit creation attempts.

```
DoSCircuitCreationEnabled 1
DoSCircuitCreationBurst 30
DoSCircuitCreationRate 3
DoSCircuitCreationMinConnections 3
DoSCircuitCreationDefenseTimePeriod 3600 seconds
DoSCircuitCreationDefenseType 2
```

{% hint style="info" %}
`DefenseType 2` will **refuse** circuit creation for the defined period if thresholds are exceeded.\
Helps prevent CPU exhaustion from malicious circuits.
{% endhint %}

### :small\_blue\_diamond:Connection Flooding Protection

Limits the rate and number of incoming connections to avoid exhaustion.

```
DoSConnectionEnabled 1
DoSConnectionDefenseType 2
DoSConnectionMaxConcurrentCount 50
DoSConnectionConnectRate 20
DoSConnectionConnectBurst 30
DoSConnectionConnectDefenseTimePeriod 24 hours
```

{% hint style="info" %}
`DefenseType 2` immediately closes excessive new connections.\
Recommended for middle and exit relays exposed to public traffic.
{% endhint %}

### :small\_blue\_diamond:Stream Abuse Protection

Protects against exit traffic generating too many streams per circuit.

```
DoSStreamCreationEnabled 1
DoSStreamCreationDefenseType 3
DoSStreamCreationRate 100
DoSStreamCreationBurst 200
```

{% hint style="info" %}
Only needed for **exit nodes**.
{% endhint %}

### :small\_blue\_diamond:Hidden Service DoS Protection

Protects your hidden service from introduction/rendezvous DoS attacks.

```
HiddenServiceEnableIntroDoSBurstPerSec 200
HiddenServiceEnableIntroDoSRatePerSec 25
HiddenServicePoWDefensesEnabled 1
HiddenServicePoWQueueRate 250
HiddenServicePoWQueueBurst 2500
CompiledProofOfWorkHash 1
```

{% hint style="info" %}
Includes:\
Proof-of-Work requirements\
Rate-limiting on intro points
{% endhint %}

### :small\_blue\_diamond:Disable Single-Hop Client Rendezvous

If you're running any type of **relay**, you can disallow single-hop client circuits to further reduce abuse, but it's completely optional.

```
DoSRefuseSingleHopClientRendezvous 1
```

***

### :small\_blue\_diamond:RTFM

For a better understanding of DoS mitigation strategies and configurations, please refer to the Anon Manual under&#x20;

[Manual](/sdk/native-sdk/manual#denial-of-service-mitigation-options)

The manual offers technical explanations and guidance to help you tailor your relay's defenses effectively.

{% content-ref url="/pages/u2rzmJTz21NEQcXIkJ4b" %}
[Manual](/sdk/native-sdk/manual)
{% endcontent-ref %}


# Standards & Guidelines

{% content-ref url="/pages/AXKkZT0QMSZjiDmCWnVv" %}
[Relay Operator Standards](/relay/guidelines/standards)
{% endcontent-ref %}

{% content-ref url="/pages/jA5Gz8oY4XzXyT97ePxF" %}
[Exit Relay Guidelines](/relay/guidelines/exit-guidelines)
{% endcontent-ref %}


# Relay Operator Standards

### Relay Family and Size

* For all relays that share an operator or administrating organization, the `MyFamily` field in the anonrc must be filled, specifying the list of all relay fingerprints. Dividing the family configurations into portions is prohibited.
* The total number of fingerprints allowed in one family is limited to the max allowed descriptor size which allows for around 400 fingerprints.
* Relay families must share a singular EVM wallet (this will be enforced by the rewards protocol).
* Operators should not frivolously declare relay families that do not exist.

### Contact

* Relay operators must have a working contact within their contact field - this can be an email, Telegram ID, or any other common communication platform identifier. It is recommended that this contact is **not** personal.

### Relay Binary

* Do not modify the core content or functionality of the anon binary
* Do not store or publish process information including any information about inbound or outbound connections.
* Only run a relay on servers or hardware that you own, control and have confidence over the security. If these assumptions change, shut your relay down.&#x20;
* Endeavour to keep your anon binary up to date.&#x20;
* Do not firewall outgoing connections, ensuring relays remain reachable to one another. .
* Make sure your Exit Relay specifies unreachable IP addresses or Ports by also declaring them as Rejected with ExitPolicy in anonrc.
* Only run a relay if you expect it to remain up and active consistently (i.e., do not run on a device that you expect to be switched off or put to 'sleep' multiple times a day)


# Exit Relay Guidelines

A guide on setting up, securing, and maintaining an Exit Relay in the Anyone Network. It covers best practices for configuration, security, and compliance to ensure safe and efficient operation.

This guide focuses specifically on running an exit relay, with focus on strengthening decentralization and making sure the network remains resilient and widely distributed. If you’re considering running an exit relay, this document will help you understand what to expect, as well as the steps needed to set up, maintain, and manage your node.&#x20;

However, some parts of this guide, such as the sections on [Security and Encryption](/relay/guidelines/exit-guidelines#security-and-encryption), can also be useful when operating a relay in the **Guard** or **Entry** roles.&#x20;

{% hint style="info" %}

#### Read the [Relay Operator Standards](/relay/guidelines/standards) to learn more about what is expected of you as an **Anyone Relay Operator**.

{% endhint %}

{% hint style="warning" %}
**Note**: \
This document offers general guidance and **does not** constitute legal advice. Legal landscapes differ by jurisdiction, so consult with a legal expert experienced in internet privacy laws before operating an exit relay.
{% endhint %}

{% hint style="danger" %}
It is important to understand that running an Exit relay requires more maintenance and security awareness than in comparison to a Middle relay. It is recommended to **never** host an Exit relay at home or other private premises.
{% endhint %}

## Operating an Exit Relay

Operating an exit relay for the Anyone Network is a vital responsibility, supporting the global effort to provide anonymity and privacy to users. As the final hop where traffic exits the encrypted network and enters the open internet, exit relays come with significant responsibilities. Operators must be mindful of the technical requirements, potential legal challenges, and the broader implications of running an exit relay.

## The Role of an Exit Relay in the Anyone Network

Exit relays are the last point where encrypted traffic leaves the Anyone Network and reaches the public internet. **The IP address of the exit relay is visible to the destination site**, ensuring the original user's IP remains hidden, thus enhancing user anonymity. A decentralized network of exit relays, spread across diverse geographic regions and legal jurisdictions, is crucial for the network's resilience. This decentralization minimizes the risk of a single entity controlling a significant portion of the network, protecting it from censorship and surveillance while maintaining operational robustness.

## Hosting Considerations for an Exit Relay

Running a successful exit relay requires careful hosting choices. These considerations will help optimize your exit relay's performance and contribute to the network's robustness.

**Choose a Relay-Friendly ISP**; Not all ISPs are ideal for exit relays. Find one that understands and supports the Anyone Protocol. Communicate clearly about exit traffic functions. Look for ISPs offering dedicated IP ranges and high bandwidth. Confirm they are comfortable with the legal responsibilities and request IP range reassignment for easier complaint management. Check out the '**VPS Relays - Hosting/Provider Discussion Thread**' on the [Anyone Discord server](/resources/support) for community discussions and considerations.

If you're affiliated with a **University**, consider hosting your exit relay there. Universities often have ample bandwidth and infrastructure. Collaborate with faculty who support internet privacy and security.

Use dedicated hardware for better security and performance. Embrace decentralization—avoid relying on a single provider or location. Spread resources across different regions and providers to enhance network resilience and prevent relay concentration. \
\
See the [Anyone Explorer Map on DePINHub.io](https://depinhub.io/projects/anyone/explorer).

## Legal Considerations for Exit Relay Operators

Operating an exit relay brings legal responsibilities, especially since it handles traffic exiting onto the open internet. Given the nature of the how an onion network works, traffic exiting from your relay may sometimes be associated with illicit activities, so it’s crucial to understand the legal framework in your country.

#### **Understanding the Legal Framework**

Different countries have different laws governing internet traffic, liability, and intermediary protections. In some jurisdictions, operators of communication services (including exit relays) may benefit from laws that shield them from liability as intermediaries, similar to how ISPs are protected. Before running an exit relay, make sure you are familiar with these laws in your region.

#### **Seeking Legal Expertise**

Consult with a legal expert who specializes in internet privacy, intermediary liability, and communication laws. Having an expert review your particular setup and jurisdiction ensures that you are operating within legal boundaries and reduces potential risks. They can help you navigate complex areas like common-carrier protections and liability for forwarded traffic.

#### **Jurisdictional Differences**

While some countries offer clear legal protections for exit relay operators, others may have stricter regulations or unclear rules. Your legal expert can guide you through understanding the nuances of your jurisdiction, including specific paragraphs or provisions that may apply. If possible, join networks of other relay operators who share legal experiences in your region.

#### **Creating a Legal Entity for Exit Relay Operations**

If you are operating an exit relay as an individual, consider setting up a legal entity, such as a non-profit organization. A legal entity provides several advantages:

#### **Reduced Personal Liability**

By operating as a formal organization, you can limit your personal liability. This setup also gives your operation more credibility, which may help when working with ISPs or law enforcement. A legal entity can provide continuity for your relay, ensuring that it continues to operate if you decide to step down.

#### **Community Engagement**

If you are part of an organization (such as a university or non-profit), consider educating others in your organization about the Anyone Protocol. Engage with your legal department to verify that they understand the purpose and function of your exit relay. Building awareness within your community helps reduce misunderstandings and builds support.

#### **Proactively Engaging with Law Enforcement**

Consider reaching out to local law enforcement agencies to educate them about Anyone and how your exit relay functions. By teaching them about the purpose of the network, we can hope to create a collaborative relationship that reduces the likelihood of misunderstandings.

#### **Build Relationships**

Contacting law enforcement before an issue arises allows you to position yourself as an expert and ally. If a legal inquiry or abuse complaint does arise, they will be more likely to view you as a cooperative partner rather than a potential suspect. Offering informational sessions or guides on how the network functions can help demystify your relay’s role and its importance for privacy online.

## Handling Abuse Complaints

Because an exit relay exposes your IP to the public, you will likely receive abuse complaints related to traffic that passes through your relay. These can range from reports of criminal activity to automated DMCA takedown requests. Here’s how to handle these situations.

Respond to complaints promptly and professionally. Automated reports are common, but it’s important to take every complaint seriously. In your responses, explain that you are operating an exit relay for the Anyone Network and are not responsible for the content of the traffic passing through it.

Include a brief explanation of how the Anyone Network functions and provide relevant legal references. For instance, if your country’s laws protect intermediary services, cite the specific regulations in your reply.&#x20;

If you receive a legal threat, such as a letter from a lawyer regarding abuse or a DMCA complaint, don’t panic. In most cases, these situations can be resolved by explaining the legal protections for intermediary services. If the situation escalates, consult your legal expert for advice on the best course of action.

## Technical Considerations for Running an Exit Relay

Technical expertise is essential when running an exit relay to ensure security, reliability, and performance. Below are some of the key technical considerations

#### **Managing Your Exit Policy**

Exit relays expose certain ports to the public internet. By default, many services and ports are allowed, but [you can adjust your **exit policy**](/sdk/native-sdk/manual#exitpolicy-policy-policy) to restrict high-risk or malicious traffic, which tends to attract abuse complaints. A **Reduced Exit Policy** allows most web services while blocking high-abuse ports, reducing the risk of receiving complaints.

#### **Security and Encryption**

Strengthen your exit relay’s security by keeping software up-to-date and using disk encryption. Disk encryption protects your relay’s private keys and other sensitive information in the event of a server breach. Secure configurations and firewall rules are also essential to safeguard against unauthorized access.

Below are some basic steps to get started, but continue researching the best methods for hardening your relay:

* Regularly apply updates to keep your system secure with the latest patches.
* Encrypt your disk to protect sensitive data, especially in case of a breach.
* Backup private keys and important information.
* SSH key authentication.
* Set firewall rules.
* Disable unused services.
* Perform regular security audits.
* Block brute-force attacks with tools such as Fail2Ban

#### **Reverse DNS and Public Information**

Set up reverse DNS entries for your exit relay that clearly indicate its purpose. Using terms like "anon-exit-relay" or "privacy-relay" can help site owners and administrators understand the nature of the traffic passing through your relay. This transparency can reduce the likelihood of receiving abuse reports and complaints.

#### **Distributed Hosting for Decentralization**

For true decentralization, avoid hosting all your relays in one country or with a single provider. Distribute your hosting across multiple regions and jurisdictions. This will make the Anyone Network robust against shutdowns and legal attacks on specific geographic locations.

## Building a DePIN Future for the Anyone Network

The network thrives on diversity, and by operating an exit relay in under-represented regions, you bolster its security and resilience. Encouraging new operators to set up relays expands the network, making it tougher for adversaries to compromise or censor it. A diverse, well-distributed relay network across various countries ensures decentralization, keeping traffic anonymized across different legal and political environments.&#x20;


# VPS Hardening & Best Practices

This guide provides essential practices and tools that VPS operators can use to secure their Linux servers, particularly in exposed or high-risk environments.

It focuses on practical, executable steps, including system hardening, SSH security, firewall configuration, intrusion prevention, and monitoring. All instructions are tested on Debian-based systems (e.g., Ubuntu), with emphasis on clarity and maintainability.

For Advanced Hardening in an automated script, take a look at: [ANyONe-secure-vm-hardening](https://github.com/ekisanon-anyone/ANyONe-secure-vm-hardening) script created by a dedicated member of the Anyone Community.

#### Let's begin!

## System Hardening and Updates

### :small\_blue\_diamond:Full system update

Keeping your system fully updated ensures your protection against known vulnerabilities and that all installed packages operate with the latest security patches.&#x20;

```bash
sudo apt update && sudo apt dist-upgrade -y
```

{% hint style="info" %}
To enable automatic System Updates: \<add instructions or link here>
{% endhint %}

### :small\_blue\_diamond:Disable Unnecessary Services

Reducing your system's attack surface starts with turning off services that aren't needed. \
Unused services may expose ports or run vulnerable software unnecessarily.

Audit running services and disable those not in use:

```bash
sudo systemctl list-units --type=service --state=running
```

Then disable with this command:

```bash
sudo systemctl disable --now <service-name>
```

#### Services you can usually disable or mask on a server operating as a relay

<table data-header-hidden><thead><tr><th width="191.88885498046875">Service</th><th>Purpose</th></tr></thead><tbody><tr><td><strong>Service</strong></td><td><strong>Purpose</strong></td></tr><tr><td><code>packagekit.service</code></td><td>Manages automatic updates graphically; not needed for headless CLI-based VPS.</td></tr><tr><td><code>snapd.service</code></td><td>Snap uses additional background daemons and mounts. It’s often unwanted bloat on servers. (Remember to <code>sudo apt purge snapd</code>)</td></tr><tr><td><code>snap.canonical-livepatch.canonical-livepatchd.service</code></td><td>Livepatching isn’t typically used on minimal or ephemeral servers. (It's usually removed by purging snapd)</td></tr><tr><td><code>multipathd.service</code></td><td>Multipath is for SAN and storage setups. Not needed on cloud VPS or simple disk configs.</td></tr></tbody></table>

#### Services you should usually keep

<table data-header-hidden><thead><tr><th width="261.9999694824219"></th><th></th></tr></thead><tbody><tr><td><strong>Service</strong></td><td><strong>Purpose</strong></td></tr><tr><td><code>dbus.service</code></td><td>Required by some utilities and desktop components. Harmless and often needed by other services.</td></tr><tr><td><code>getty@tty1.service</code></td><td>Provides login on local TTY; not harmful,  but optional to disable in headless environments.</td></tr><tr><td><code>networkd-dispatcher.service</code></td><td>Helps with DHCP Netplan events; required on Netplan-managed systems.</td></tr><tr><td><code>polkit.service</code></td><td>Used for user privilege escalation. Needed if you use desktop tools or sudo based GUI operations; may be safe to disable on hardened CLI-only systems.</td></tr><tr><td><code>ssh.service</code></td><td>Keep for remote access.</td></tr><tr><td><code>systemd-networkd.service</code></td><td>Manages network interfaces; critical for connectivity on minimal systems.</td></tr><tr><td><code>systemd-resolved.service</code></td><td>Handles DNS; often required unless using custom resolvers or DNS tools.</td></tr><tr><td><code>systemd-timesyncd.service</code></td><td>Keeps system clock accurate (important for anon).</td></tr><tr><td><code>systemd-journald.service</code></td><td>System logging; required!</td></tr><tr><td><code>systemd-logind.service</code></td><td>Handles user logins and sessions; usually fine to leave.</td></tr><tr><td><code>systemd-udevd.service</code></td><td>Manages device nodes; needed.</td></tr><tr><td><code>user@1000.service</code></td><td>Your user session; leave it alone.</td></tr></tbody></table>

***

## SSH Security

SSH is the lifeline of remote management, securing it is critical.

### :small\_blue\_diamond:Change Default SSH Port

Changing the SSH port from the default `22` to a custom value (e.g., `52231`) helps reduce exposure to automated scans and brute-force attacks. While not truly secure, it adds a layer of obscurity that can reduce low-effort intrusion attempts.

Edit `sshd_config`

```bash
sudo nano /etc/ssh/sshd_config 
```

Look for **`#Port 22`** and change it to to anything else, and for the sake of this example we just randomly selected `52231`:

```ini
Port 52231
```

Then restart the SSH service.

```bash
sudo systemctl restart sshd.service
```

### :small\_blue\_diamond:Enable Login Banners

Login banners warn users that the system is monitored and restricted. These messages can serve legal or policy purposes by clearly stating that unauthorized access is prohibited.

Edit `/etc/issue.net` with a warning message.

```bash
sudo nano /etc/issue.net
```

Replace the contents and save it with something like:

```ini
ALERT! You are entering a secured area! Your IP, Login Time, and Username have been noted and have been sent to the server administrator!
This service is restricted to authorized users only. All activities on this system are logged.
Unauthorized access will be fully investigated and reported to the appropriate law enforcement agencies.
```

Edit `/etc/ssh/sshd_config` and look for the banner option.

```bash
sudo nano /etc/ssh/sshd_config
```

```ini
# no default banner path
#Banner none
```

Set it to the updated `issue.net` file.

```ini
Banner /etc/issue.net
```

Restart the SSH Service.

```bash
sudo systemctl restart sshd.service
```

{% hint style="info" %}
Suggestion provided on AskUbuntu.com:\
<https://askubuntu.com/questions/420375/how-to-add-legal-banner-in-etc-issue-and-etc-issue-net-in-ubuntu>
{% endhint %}

### :small\_blue\_diamond:Disable Root Login (Recommended)

Disabling direct root login via SSH helps prevent attackers from brute-forcing the root account. Instead, users should authenticate with non-root accounts and escalate privileges securely using `sudo`.

{% hint style="info" %}
Read more about typical SSH Key Scanning at:\
<https://www.ssh.com/blog/ssh-key-scan-attack-honeypot>
{% endhint %}

If you've followed the guide so far you already know how to edit `/etc/ssh/sshd_config`.\
\
Set:

```ini
PermitRootLogin no
```

### :small\_blue\_diamond:Set Up SSH Key Authentication (Recommended)

SSH key authentication replaces passwords with cryptographic key pairs, significantly reducing the risk of brute-force attacks. It’s a foundational best practice for secure remote access.

Generate key pair (on a local machine):

```bash
ssh-keygen -t ed25519
```

{% hint style="success" %}
Generating public/private ed25519 key pair.\
Enter file in which to save the key (/root/.ssh/id\_ed25519): `[Press ENTER]`\
Created directory '/root/.ssh'.\
Enter passphrase (empty for no passphrase): `[Press ENTER]`\
Enter same passphrase again: `[Press ENTER]`\
\
Your identification has been saved in /root/.ssh/id\_ed25519\
Your public key has been saved in /root/.ssh/id\_ed25519.pub
{% endhint %}

Copy public key to the server:

```bash
ssh-copy-id -p 52231 user@server_ip
```

{% hint style="success" %}
INFO: Source of key(s) to be installed: "/root/.ssh/id\_ed25519.pub"\
The authenticity of host 'server\_ip (server\_ip)' can't be established.\
ECDSA key fingerprint is SHA256:\<redacted>.\\

\
Are you sure you want to continue connecting (yes/no/\[fingerprint])? yes\
\
INFO: attempting to log in with the new key(s), to filter out any that are already installed\
The authenticity of host 'server\_ip (server\_ip)' can't be established.\
ECDSA key fingerprint is SHA256:\<redacted>.\\

\
Are you sure you want to continue connecting (yes/no/\[fingerprint])? yes\\

\
INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys\
\
ALERT! You are entering a secured area! Your IP, Login Time, and Username have been noted and have been sent to the server administrator!\
This service is restricted to authorized users only. All activities on this system are logged.\
Unauthorized access will be fully investigated and reported to the appropriate law enforcement agencies.\\

\
user\@server\_ip's password:

\
Number of key(s) added: 1

Now try logging into the machine, with: "ssh -p '52231' 'user\@server\_ip'"\
and check to make sure that only the key(s) you wanted were added.
{% endhint %}

Try to log in to the server from your local machin with the new key:

```bash
ssh -p '52231' 'user@server_ip
```

On the server, disable password authentication in `sshd_config`:

```ini
# To disable tunneled clear text passwords, change to no here!
#PasswordAuthentication yes
```

Set:

```ini
PasswordAuthentication no
```

{% hint style="info" %}
You can find detailed descriptions of the commands used for this tutorial at:

<https://www.ssh.com/academy/ssh/keygen>

<https://www.ssh.com/academy/ssh/copy-id>

<https://www.ssh.com/academy/ssh/sshd_config>
{% endhint %}

***

## Firewall & Network Protection

### :small\_blue\_diamond:UFW Firewall

UFW (Uncomplicated Firewall) makes it easy to manage iptables and control which services are exposed to the internet. Setting a default-deny policy and allowing only essential ports helps contain threats and limit exposure.

```bash
sudo apt install ufw -y
```

#### Default Policy

```bash
sudo ufw default deny incoming
sudo ufw default allow outgoing
```

#### Allow Essential Ports

```bash
sudo ufw allow 52231/tcp    # Custom SSH
sudo ufw allow 53/udp       # DNS (if applicable)
sudo ufw allow 9001/tcp     # Example: anon service
```

Enable the service.

```bash
sudo ufw enable
```

To check the status of UFW:

```bash
sudo ufw status verbose
```

{% hint style="info" %}
When running the [installation script](/relay/start/install-anon-on-linux), UFW is offered as an option to enable access for SSH and ORPort.\
\
Read more about UFW on the official Ubuntu documentation:\
<https://help.ubuntu.com/community/UFW>
{% endhint %}

***

## Intrusion Detection and Abuse Prevention

Automated protection against brute-force and scanning behavior.

### :small\_blue\_diamond:Fail2Ban

Fail2Ban monitors system logs for failed login attempts or suspicious behavior, then bans the source IP using firewall rules. It's highly effective for deterring brute-force attacks against SSH and other services.

{% hint style="info" %}
Find the official documentation and repository for Fail2ban at:

<https://github.com/fail2ban/fail2ban>
{% endhint %}

#### Install Fail2Ban.

```bash
sudo apt install fail2ban -y
```

#### Configure Fail2ban

Instead of modifying the default `jail.conf`, create a local configuration.

```bash
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
sudo nano /etc/fail2ban/jail.local
```

In the `[DEFAULT]` section, adjust the following parameters as needed:

```ini
[DEFAULT]
bantime  = 10m
findtime = 10m
maxretry = 5

```

{% hint style="info" %}
`bantime` - Duration an IP is banned (e.g., 10 minutes).

`findtime` -  Time window to count failures (e.g., 10 minutes).

`maxretry` - Number of allowed failures before a ban (e.g., 5 attempts).
{% endhint %}

#### Enable SSH Protection

Ensure the `[sshd]` jail is enabled.

```ini
[sshd]
enabled = true
port    = ssh
logpath = %(sshd_log)s
backend = %(sshd_backend)s
```

If you've changed the SSH port (e.g., to 52231), update the `port` value accordingly.

```ini
port = 52231
```

#### Start and Enable Fail2Ban

```bash
sudo systemctl enable fail2ban
sudo systemctl start fail2ban
```

Monitor Fail2Ban Status

Check the status of Fail2Ban and its jails.

```bash
sudo fail2ban-client status
sudo fail2ban-client status sshd
```

To unban an IP, use the `set` function:

```bash
sudo fail2ban-client set sshd unbanip <IP_ADDRESS>
```

***

## Monitoring

Basic system monitoring helps detect when something is wrong; like resources, failed services, or suspicious activity. Before it becomes a full outage or compromise.

### :small\_blue\_diamond:Install Watchdog (optional)

```bash
sudo apt install watchdog -y
sudo systemctl enable --now watchdog
```

Configure `/etc/watchdog.conf` for system checks like disk, memory, or network loss.

{% hint style="info" %}
See Ubuntu Man pages for detailed description on how to modify the configuration file for Watchdog:\
<https://manpages.ubuntu.com/manpages/xenial/man8/watchdog.8.html>
{% endhint %}


# Hardware Setup

The Anyone Hardware protects your privacy and enables you to earn crypto token rewards!

## Welcome to your Hardware!

You are now part of a movement to truly take our privacy back. Your hardware gives you instant access to a secure, private connection for everyday browsing. For those who want to go further, it also unlocks the ability to support the network and earn crypto by contributing bandwidth.&#x20;

Choose the option for you and get started with your setup now, or scroll further to find out more about the device!&#x20;

### Get setup with a private Wi-Fi connection in under a minute:

{% content-ref url="/pages/efskHkmGvzYumup6cazh" %}
[Router Mode - Quick Install](/hardware/setup-guides/router-mode)
{% endcontent-ref %}

### Protect and earn crypto tokens by contributing to the network (full setup).

{% content-ref url="/pages/oM48xnHMqLOC37BX5uln" %}
[Relay Mode](/hardware/setup-guides/relay-mode)
{% endcontent-ref %}

&#x20;

## What's in the box?

* [ ] **Anyone Router Device**
* [ ] USB-C Power Cable
* [ ] USB Wi‑Fi adapter for dual-band connection
* [ ] USB thumb drive for hardware updates
* [ ] Quick‑start guide & sticker

<div align="left"><figure><img src="/files/w5y0Bhih0nZoimGGZJ8O" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/IhjWWJyTGMzgtxGg6CbG" alt="" width="563"><figcaption></figcaption></figure></div>

To find out more about the device - see [Overview & Specifications](/hardware/overview)!

## QuickStart - Router Mode Setup (3 minute guide)

Follow these simple steps to set up your Anyone Router in **Router Mode.** Perfect for sharing your home network traffic securely. A detailed description can be found at [Router Mode Installation](/hardware/setup-guides/router-mode).

***

### Power up & Enter Setup Mode

{% hint style="success" %}

1. **Connect the power cable to the back of the device**
2. **Wait for lights to stabilize (blue swirling -> red steady).**
3. **Hold the blue button down for 3s to enable the Wi-Fi captive portal.**
   {% endhint %}

![](/files/p41RlugxytCWpG1J4Ypt)    ![](/files/2aqii5IMiuR8Vq0g8R0k)\
Use a computer, battery pack, or power adapter to power your device, minimum 15W.

***

### Connect & Launch Wizard

{% hint style="success" %}
**Find the new W-iFi network:**

`relayup_<serialID>`

**Password:**

`anyone.io`

![](/files/tylU59eFGxuGBChUZJGK)
{% endhint %}

The captive portal opens up automatically. \
\
If not open a browser to:\
[http://relayup.local](http://relayup.local/)\
or [http://10.42.0.1](http://10.42.0.1/)

{% hint style="success" %}
**Accept Terms, log in with default password `admin`, and continue.**

![](/files/AZf1lxyHLDJSXejaRcVr)    ![](/files/IDQMTkwdZ7H8Tb2K3bDK)
{% endhint %}

***

### Choose Router mode

{% hint style="success" %}
**In the wizard:**

* Select **Router Only Setup** (no relay traffic)
* Choose your uplink (wired or Wi-Fi)
  * Optional: plug in USB Wi-Fi adapter for dual-band hotspot capability

![](/files/zoJOJ3xVoGV8DW8udyhF)    ![](/files/atnlkqx3Qxh55GtQS1FN)&#x20;
{% endhint %}

{% hint style="success" %}
Set up your own hotspot name and password

![](/files/LauW0xd5zDg6v9i7zbMs)
{% endhint %}

***

### What happens now

* The device installs settings and reboots automatically
* LED lights turn green indicating a successful uplink

Connect any client device to the router's hotspot to have its internet traffic routed through Anyone’s secure network

LED pulsing <mark style="color:blue;">Anon Blue</mark> = Router Running

{% hint style="info" %}
For home traffic, install the [**Anyone Browser**](/connect/ios#anyone-browser-app-store) or the **Anyone Desktop VPN** (coming soon) on your client devices
{% endhint %}

***

### Watch the setup in action

{% embed url="<https://www.youtube.com/embed/r81ls2N9guM?si=AOArawI2s4W-_7Tt>" %}

* **Follow the** [**Router Mode Steps**](#quickstart-router-mode-setup-3-minute-guide) from above to **get started instantly!**
* Or choose the [**Relay Mode**](#optional-relay-mode-advanced) to **contribute your bandwidth** while earning **contribution rewards**.

***

### After Setup - Next Steps

Head to the Control panel at [https://relayup.local](https://relayup.local/) or the shown IP from above

{% hint style="danger" %}
**IMPORTANT:**\
[Change your admin password](/hardware/setup-guides/controlpanel#change-password)
{% endhint %}

See the [Control Panel Walkthrough](/hardware/setup-guides/controlpanel) for full details of all the available settings.&#x20;

{% content-ref url="/pages/7tmjsFRrKszseNmFyA6v" %}
[Overview & Specifications](/hardware/overview)
{% endcontent-ref %}

***

***

### Relay Mode (Advanced)

Running a relay with an Anyone hardware device is the easiest way to support the network and start earning $ANYONE tokens. You’ll contribute your home internet bandwidth while benefiting from a special rewards pool reserved just for hardware relays.

Ready to get started? Follow the [Relay Setup Guide →](/hardware/setup-guides/relay-mode)

***

<div align="left"><figure><img src="/files/q7p6FkB2oemnvft1kVFO" alt="" width="563"><figcaption></figcaption></figure></div>


# Overview & Specifications

## Introducing the **Anyone Router** <a href="#introducing-the-ator-relay" id="introducing-the-ator-relay"></a>

A robust hardware solution designed to seamlessly integrate into your digital setup. Equipped with a **dual-Cortex 1.5GHz CPU**, **4GB LPDDR4 RAM**, and **64GB eMMC Storage**, this device offers reliability and performance for a variety of tasks. With features like **1000 Mbps Ethernet**, **WiFi 802.11 n/ac** connectivity, and **USB A OTG port**, it ensures seamless data transfer and versatile connectivity options.

<div align="left"><figure><picture><source srcset="/files/7H4VADO286lKAi34yESq" media="(prefers-color-scheme: dark)"><img src="/files/nJhp0GmNPmer7I1nwOSJ" alt="" width="375"></picture><figcaption></figcaption></figure></div>

### Input/Output Interface <a href="#input-output-interface" id="input-output-interface"></a>

![](/files/PcibOpBmoXnPc9f52sMS)![](/files/aGBo1iu5ZFxLjnHZWi8q)

### Specifications

| **Processor**                                                                                                                          | **GPU**                                                                                     | **Encryption**                                                    |
| -------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| Rockchip RK3399-T, Hexa-core 64-bit SOC Dual Cortex®-A72, frequency 1.5-GHz with quad Cortex® A53, 1Ghz with separate NEON coprocessor | Arm Mali™ T860MP4 GPU, OpenGL ES 1.1 /2.0 /3.0 /3.1 /3.2, Vulkan 1.0, Open CL 1.1 1.2, DX11 | Cryptographic Co-Processor with Secure Hardware-Based Key Storage |
| **Memory**                                                                                                                             | **Storage**                                                                                 | **Bluetooth**                                                     |
| 4GB LPDDR4-3200 SDRAM                                                                                                                  | 32GB NAND Flash (up to 128GB)                                                               | Bluetooth 5.0, BLE                                                |
| **USB**                                                                                                                                | **Wireless**                                                                                | **LAN**                                                           |
| 1x USB 3.0 OTG                                                                                                                         | 2.4 GHz & 5.0 GHz IEEE 802.11ac wireless                                                    | 1x Gigabit Ethernet                                               |
| **Power**                                                                                                                              | **Dimensions**                                                                              |                                                                   |
| Power adapter with USB type C port minimum (5V3A) 15W                                                                                  | 104.3mm x 109.6mm x 24.22mm                                                                 |                                                                   |

Security is a top priority with the **Anyone Relay**, featuring an **encryption chip** and **CryptoAuth key generation** to protect your data. Its sleek anodized aluminum build not only enhances durability but also allows for easy wall-mounting. Beyond its hardware capabilities, the **Anyone Relay** plays a crucial role in the **Anyone network**, enabling users to contribute bandwidth and computing power effortlessly. Moreover, it will be able to route home internet traffic through the **Anyone network**, ensuring enhanced security and access to anonymous services. With its advanced technology and user-centric design, the **Anyone Relay** offers a reliable solution for navigating the digital realm with confidence.

<div align="left"><figure><img src="/files/X3HnmvWksmdhH2J1poBv" alt="" width="375"><figcaption></figcaption></figure></div>

### Light indicators <a href="#light-indicators" id="light-indicators"></a>

<figure><img src="/files/axx64eUHCGWTJFrKBef4" alt="" width="563"><figcaption></figcaption></figure>

<figure><img src="/files/8JtdqD7F3ArWQW0Rkyak" alt=""><figcaption></figcaption></figure>

### Internal Components

<figure><img src="/files/vbJ2Sz0WB6229cnwDzh2" alt=""><figcaption></figcaption></figure>


# Setup Guides

Whether you want to protect your privacy immediately, run a relay and contribute to the Anyone Network, use some of our new hosting features, or want a complete overview of the relay control panel - choose the setup guide for you!

{% content-ref url="/pages/efskHkmGvzYumup6cazh" %}
[Router Mode - Quick Install](/hardware/setup-guides/router-mode)
{% endcontent-ref %}

{% content-ref url="/pages/oM48xnHMqLOC37BX5uln" %}
[Relay Mode](/hardware/setup-guides/relay-mode)
{% endcontent-ref %}

{% content-ref url="/pages/nxlE4qjfw8K5K8fuU7qi" %}
[Control Panel Walkthrough](/hardware/setup-guides/controlpanel)
{% endcontent-ref %}


# Router Mode - Quick Install

This guide will walk you through how to set up the Anyone Router in Simple Routing Mode.

### Welcome to your Anyone Router.

The Anyone Router protects your home traffic by creating a **secure Wi-Fi hotspot** that routes clients through the Anyone Network - an unloggable global privacy network.&#x20;

{% hint style="info" %}
About the **Anyone Network**\
Unlike almost all VPNs, which run central servers that track and log your traffic, the Anyone Network provides network privacy that *cannot* be traced. The Network uses **onion routing**, which means that your traffic flows through **multiple VPN tunnels** to fragment your data. \
\
Find out more about the network at [https://anyone.io/network](<https://anyone.io/network >).

For more information about network speed, jump to [#extra-performance](#extra-performance "mention").
{% endhint %}

### Power On&#x20;

The device is powered by USB-C, which is plugged into the back-left of the unit. Once plugged in, the unit will boot up with green loading lights, and end with all lights red.&#x20;

<figure><img src="/files/0nIt1Ix4m9AFrq4TS36z" alt="" width="563"><figcaption></figcaption></figure>

### Enter Setup Mode

To setup your unit for the first time, or change the mode, you need to put the device in **setup mode** once it is running. This is done by pressing the blue button on the side of the device for 3 seconds.&#x20;

<figure><img src="/files/Kxup8xZZzyksry0SM1Jb" alt="" width="563"><figcaption></figcaption></figure>

The lights on top of the relay should glow blue like below:

<figure><img src="/files/iwxQpv7TX7J2r4y8ME6E" alt="" width="188"><figcaption></figcaption></figure>

This will trigger the creation of a new Wi-Fi connection originating from the device! When you first set up, the Wi-Fi name will start with `relayup` and have some digits at the end. Connect to this from your phone or computer.&#x20;

{% code title="Wi-Fi Details" %}

```yaml
Name: relayup_XXXXXX (this will be 6 random digits)
Password: anyone.io
```

{% endcode %}

Once you're connected, you should get an automatic pop up page like below:

<figure><img src="/files/Q894tnTfL1wHHyWTpyV4" alt="" width="480"><figcaption></figcaption></figure>

### Setup Your Secure Wi-Fi

You are now on the **Setup Mode** wizard. This is a password protected wizard used by the device owner - it has a different password to the Wi-Fi, as it is only used by you. After accepting the hardware terms, proceed to the next page using the password **`admin`.**

{% code title="Setup mode password" %}

```
admin
```

{% endcode %}

<figure><img src="/files/i0zT4QQptbeGJSy9ZRqQ" alt="" width="480"><figcaption></figcaption></figure>

#### Choosing your Mode

After entering the password, you will be presented with two modes. To protect your home network in a few simple steps, choose that first option - **Simple Setup.**&#x20;

<figure><img src="/files/E1TOuZ1lq8HFj17v7p6V" alt="" width="480"><figcaption></figcaption></figure>

{% hint style="info" %}
The other option - Manual Setup - lets you also earn cryptocurrency rewards by contributing your bandwidth to the network, but requires a few more steps. Head over to [Relay Mode](/hardware/setup-guides/relay-mode) to see the full list of options!
{% endhint %}

#### Name your hotspot and create a password

If you wish, you can change the name of the hotspot's Wi-Fi name. To connect to the hotspot, the default password is **`anyone.io`.** It is recommended to change this to a secure password, remember to note it down and save securely!

<figure><img src="/files/aWysT07T7mHLiqTmsopy" alt="" width="480"><figcaption></figcaption></figure>

**What is your preferred connection method?**

Select your preferred option for the Anyone Router to connect to the your home router, for it to be able to have an Internet connection.&#x20;

**Ethernet**\
Press the Ethernet logo use a Cabled Ethernet connection, make sure an Ethernet cable is attached between your home router and the Anyone Router. See the status indicator to confirm the connection status.

**Wi-Fi**\
Press the Wi-Fi logo to connect the Anyone Router to your home router wirelessly.

{% hint style="info" %}
The Wi-Fi password can not contain any of the following characters:\
&#x20;`#` `'` `\` `=` `´` `*`

If it includes any of these characters, please change the password before attempting to connect the device.
{% endhint %}

<figure><img src="/files/lO0wbA5HflBehz6cxOdp" alt="" width="480"><figcaption></figcaption></figure>

If using Wi-Fi, choose the name of your home router, input password and press **Connect** to confirm the connection, press **PROCEED** upon confirmation.

<figure><img src="/files/AtNx50zvUgaBz1Po68Cv" alt="" width="480"><figcaption></figcaption></figure>

### Setup is finished!

The Anyone Router will now restart to apply the settings, wait for the Hotspot to show in your list of available Wi-Fi connections and connect to it with when available.

<figure><img src="/files/Zg7YKkdtX6Fwel6YCMkA" alt="" width="480"><figcaption></figcaption></figure>

Your router should now be producing a secure Wi-Fi hotspot! This will be accessible to anybody in the vicinity of the device.&#x20;

### Login to the Relay Control Panel and change settings &#x20;

If you wish to change settings, such as switching the hotspot off, changing the Wi-Fi password, or switching to relay mining mode, you can reopen the settings page. There are two ways to go to settings:

**While connected to your home router** \
This is if you are connected to your original home internet, and your Anyone router is also connected \
**Go to**[ **http://relayup.local**](< http://relayup.local>)

**While connected to the Anyone hotspot**\
This is if you are connected to the Wi-Fi hotspot created by the Anyone hardware.\
**Go to** [**http://10.42.0.1**](http://10.42.0.1)

This is the main page of the Anyone Control Panel in Router mode. To change settings, press "**Go to Relay Control Panel >**" and login with the **`admin`** password to access the settings.

<figure><img src="/files/Qt61oGE4iwBc8LyikYwT" alt="" width="480"><figcaption></figcaption></figure>

### Extra: Performance&#x20;

The Anyone Network is **substantially more secure** than typical VPN Networks as it uses three concurrent VPN tunnels to push your traffic. This ensures that no single server can track your usage. By default, the network creates circuits with well distributed servers to ensure they are all operated by different individuals. Both of these factors mean that the network has more overheads than a simple VPN.&#x20;

However, the Anyone Network is made up of a global set of thousands of relay servers, incentivized with the $ANYONE cryptocurrency, which makes it the most performant onion routing network in the world. There are also other ways to improve performance further. &#x20;

#### Use US-only mode

The Anyone Router has the option to prefer circuits *built* locally in your region, this may reduce latency and increase the speed of the VPN.&#x20;

Go to **Interface > Network Settings**, In the **Router Settings** box you have the option between **Global** and **America**, select **America** to prefer circuits in US only.&#x20;

Press **APPLY** then confirm with **Save**, then press **REBOOT** and confirm by choosing **REBOOT** again, the Router will now restart with these new settings.&#x20;

<figure><img src="/files/fItJb8XF1rgDK8kuRhyD" alt="" width="563"><figcaption></figcaption></figure>


# Relay Mode

This guide will walk you through setting up your Anyone Hardware Relay using either a wireless or wired connection to access the internet. Let's #RelayUp!

### 1.   Powering up the Device

Begin by connecting the power cable to a suitable power outlet with **minimum 15W** at (**5V 3A**) and plug the supplied USB-C connector into the rear of the Relay.&#x20;

The Relay will boot up, and you will see <mark style="color:green;">**green**</mark> lights rotating.&#x20;

<div align="left"><figure><img src="/files/3XzI2HdqQFUgM2UzocnO" alt="" width="188"><figcaption></figcaption></figure></div>

### 2.   Wait for the Device to start

Once started, it will display a steady <mark style="color:red;">**red**</mark> light.

<div align="left"><figure><img src="/files/yYbo58byXlBfsfU7zFnQ" alt="" width="188"><figcaption></figcaption></figure></div>

{% hint style="danger" %}
If the all lights of the Relay are pulsing in <mark style="color:red;">Red</mark> as shown below, ensure that you are using a power outlet with **minimum 15W** at (**5V 3A**), or the Relay will not function properly!
{% endhint %}

<div align="left"><figure><img src="/files/VMh2kezZD6ETyEKLskh1" alt="" width="188"><figcaption></figcaption></figure></div>

### 3.   Enabling the WiFi Pairing mode

Press and hold the <mark style="color:blue;">**blue**</mark> physical button on the side of the device for **3 seconds** and release it to activate the setup mode. \
\
The top part of the lights will pulse <mark style="color:blue;">**blue**</mark> when the WiFi hotspot is enabled and ready for connections.

<div align="left"><figure><img src="/files/iwxQpv7TX7J2r4y8ME6E" alt="" width="188"><figcaption></figcaption></figure></div>

### 4.   Connect to the activated WiFi hotspot.

You can now connect to the Relay via WiFi to proceed with the setup, scan for nearby devices, connect to `relayup_<yourserialID>` where the SSID contains your relays serialID.

#### Use the following credentials:

\
**SSID:** `relayup_<yourserialID>`\
**Pre-shared key (PSK):** `anyone.io`\
\
*(Relays on versions below 2.0.0 should use PSK:* `ianon.io`*)*

<div align="left"><figure><img src="/files/IJ6Ry76dfjXgu1PQSmbB" alt="" width="298"><figcaption></figcaption></figure></div>

### 5.   Access the Setup Wizard

If the captive portal doesn't open automatically in your browser, navigate to \
[http://relayup.home](http://relayup.home:80), or via the IP, [http://10.42.0.1](http://10.42.0.1:80)\
\
Alternatively, access your relay on the Ethernet IP address to set it up, but remember to activate the setup mode  in [Step 3](https://docs.anyone.io/hardware/setup-guides/pages/oM48xnHMqLOC37BX5uln#id-3.-enabling-the-wifi-pairing-mode) first.

#### Read and Agree to accept the Terms of Service if you wish to proceed.&#x20;

<figure><img src="/files/dgCArgBagk0NKWzaVO8H" alt=""><figcaption></figcaption></figure>

### 6.   Authenticate to proceed with the setup

Log in with the default credentials below and proceed following the instructions.\
(You can change this password in the control panel after setup.)

**Default password:** `admin`

<figure><img src="/files/VzXf0NuNOmraSldRiFze" alt=""><figcaption></figcaption></figure>

### 7.   Mode selection

<figure><img src="/files/lPQ9DvreDJGyOaQJLjHM" alt=""><figcaption></figcaption></figure>

## Relay Setup

<figure><img src="/files/YDRgskiOzoz4g1yMx5jt" alt=""><figcaption></figcaption></figure>

### 8. Configure your internet connection

{% hint style="success" %}

#### Options:

The Relay can be configured to connect to your Network Router using either an Ethernet cable or WiFi to access the Internet.
{% endhint %}

<figure><img src="/files/xNLtPK2mnC2MZJEh9Dz1" alt=""><figcaption></figcaption></figure>

#### Ethernet

Connect an Ethernet cable to the device's Ethernet port and ensure that the message **"Ethernet recognized"** appears if you prefer a wired internet connection.\
\
Proceed to the Next step..

#### WiFi

If you prefer a WiFi connection, ensure that no Ethernet cable is inserted into the device, as this will prioritize the Ethernet connection over WiFi.

{% hint style="info" %}
The Wi-Fi password can not contain any of the following characters:\
&#x20;`#` `'` `\` `=` `´` `*`

If it includes any of these characters, please change the password before attempting to connect the device.
{% endhint %}

Select your Network.

<figure><img src="/files/1Vbtkcgz68Y0oxcFmTVj" alt=""><figcaption></figcaption></figure>

Enter the Passkey.

<figure><img src="/files/awckCtUtXHWPzsBKqnKJ" alt=""><figcaption></figcaption></figure>

### 9.   Relay Information

Enter your preferred nickname and email address in the Relay Contact Information.\
The email address must be valid for contact purposes.

{% hint style="warning" %}
**Nickname** only accepts between 1-19 characters, only \[a-zA-Z0-9] and no spaces.\
*It is recommended not to use a personal email address, instead create a new address for the purpose.*
{% endhint %}

<figure><img src="/files/PE6B9jLr9wps3Tv5Ee5W" alt=""><figcaption></figcaption></figure>

### 10.   Recognition Rewards

Enter your Ethereum wallet address to register for rewards in the Rewards Program.\
Select **Next** to skip this step if you do not wish to enter a personal wallet address.

<figure><img src="/files/ejBEQHpo40N8gRzawcVN" alt=""><figcaption></figcaption></figure>

### 11.   Default port for Relay traffic

The port can be changed to **suit** your needs if the default **9001** is already in use by another device on the same network to prevent routing conflicts.

<figure><img src="/files/cTPLEy17PlfR6bLMiU5F" alt=""><figcaption></figcaption></figure>

### 12.   Parallel Relay & Router mode

<figure><img src="/files/kxE0kIOPGDbHzQm7Ewj9" alt=""><figcaption></figcaption></figure>

You can now choose whether to enable **Router Mode** for devices connecting to the hardware's WiFi hotspot.

This does not interfere with your relay's traffic. Instead, it uses the **Anon Client** to route all incoming traffic, including DNS requests, through the **Anyone Network**, encrypting the traffic and hiding the client's origin.\
\
Read more about the Router Mode features and functionality [here](/connect/hardware).<br>

#### Secondary WiFi Support

If the option appears grayed out, you can click **Yes** to learn more about it.

In this case, the device is missing a USB WiFi adapter needed to enable the second WLAN interface, but Ethernet is available. The latest batches of the hardware device come with an adapter.\
\
![](/files/algwEAu34yKn6pN6kJvP)

Currently, the device supports only one model for enabling WiFi-to-WiFi router functionality. To enable this feature, acquire a <mark style="color:blue;">**TP-Link (TL-WN725N) USB WiFi Adapter**</mark>, plug it in, and restart the device.

Alternatively, you can select **Ethernet** as your Wide Area Network (WAN) connection to enable the option.

Click **Yes** to proceed if your device has all the necessary equipment plugged in.

<figure><img src="/files/i7AWnPurE8UGyPGiHcln" alt=""><figcaption></figcaption></figure>

Name your hotspot however you like and set a personal passkey.

Be sure to save your credentials if you plan to share them with others to join your **Anyone Network Hotspot** or if you need to run the setup wizard again.

<figure><img src="/files/ry94gso2Rrp4aIXQsALB" alt=""><figcaption></figcaption></figure>

### 13.   Complete Setup

The setup is now complete, and the Relay will restart automatically.

#### Good job!

<figure><img src="/files/Vki5VP6r3UVZ0vDTGu7Z" alt=""><figcaption></figcaption></figure>

### Check Light indicators for Connectivity

Depending on whether a wired **Ethernet** or a wireless **WiFi** connection was selected in the previous steps, the corresponding indicator light will turn <mark style="color:green;">**green**</mark>, both physically on the device and in the control panel.

Read more about the **LED indicators** under [**Description and Specifications**](/hardware/overview).

<div align="left"><figure><img src="/files/bUz6JNUQL03L9TMyzAHx" alt="" width="188"><figcaption><p><strong>WiFi enabled</strong></p></figcaption></figure> <figure><img src="/files/v7H35JU7eHuLLJHOxw4c" alt="" width="188"><figcaption><p><strong>Ethernet enabled</strong></p></figcaption></figure></div>

### Next step for Relay Operations:

To allow traffic to reach your device you will need to create a **Port Forwarding Rule** in your network router to ensure the Relay's reachability on the Anon network.

{% hint style="success" %}

### Requirements for confirming reachability

**Port forward**\
Configure a port forward in the router. \
[Instructions can be found here. ](/hardware/troubleshooting/router-port-forwarding)\
\
**Public IPv4 address**\
Ensure the router has an exclusive public IPv4 address for the Relay's reachability. \
[More information can be found here.](/hardware/troubleshooting/diagnosing-cgnat-and-public-ipv4)
{% endhint %}

### Connect to the Relay Control Panel (RCP)

From a device connected to the same network as the Relay, browse to <http://relayup.local> or the IP of the device and log in using the following Credentials:

* **Username**: `relayup`
* **Password**: `admin`

{% hint style="info" %}
*If the DNS name `relayup.local` doesn't resolve to show the RCP login screen in your browser:*\
*See* [*Relay Control Panel > Home*](broken://pages/r6k1tGqfNcH1CtHH9oAz) *for help finding the **LAN IP** of your device to use instead.*
{% endhint %}

<figure><img src="/files/EhLdyV6o0UQ2fTHpEveh" alt=""><figcaption></figcaption></figure>

### Reachability and Bandwidth Self-Tests

On the '**Home**' page, under the '**Network**' section, check for the "**Reachability**" status indicated with "**VPN OR-Port** \[`status`]."&#x20;

The Reachability and Bandwidth self-tests take a few minutes to perform. \
Check the logs in the control panel for more details on the process.&#x20;

<div align="left"><figure><img src="/files/cGdUSjWD9lo5QoWlGgZI" alt="" width="375"><figcaption></figcaption></figure></div>

## Reachability is Confirmed!

<div align="left"><figure><img src="/files/semprYgIHF0lhhLlpRZe" alt="" width="188"><figcaption></figcaption></figure></div>

Once the "Reachability" status is '**OK'**, all lights on the Relay will start pulsing in the Anon <mark style="color:blue;">**blue**</mark> color, indicating a successful setup.&#x20;

**Congratulations! Your relay is now ready to provide bandwidth to the Anyone Network, and with some additional steps, enhance the privacy in your daily Internet use if you also enabled the Router feature, and receive contribution rewards!**

### If you enabled the router mode!

Connect to the available WiFi **SSID** that you configured in the setup wizard and use it like any other network to browse the web anonymously.\
Ensure your personal security is up to date as well. The connection doesn't provide all-encompassing protection for your web traffic; it merely encrypts data in three layers before exiting the onion routing, hiding the origin of users. Make sure your applications, browser, and operating system settings are also secure.\
\
Additional steps:

* Confirm your anonymous IP at <https://check.en.anyone.tech>.
* Take a moment to visit our homepage mirror, located only inside the **Anyone Network**:\
  <http://anyone.anon>

Which resolves to the hostname:\
**6zctvi63m7xxbd34hxn2uvnaw5ao7sec4l3k4bflzeqtve5jlehz6tyd.anon**

## What's next?

#### Claim your Relay in the Relay Dashboard!

By Claiming the Relay on the **Relay Dashboard** you can start accruing rewards. Follow the link below to find out more about how to access the dashboard.

{% hint style="success" %}

#### Note:

It may take up to 24 hours for the Relay Dashboard hosted on Arweave to recognize and verify your relay on the network. Please stay tuned and periodically check the dashboard to claim your relay.
{% endhint %}

{% content-ref url="/pages/rhCcL6zm8kH4vyJeYwR7" %}
[Accessing Dashboard](/dashboard/access)
{% endcontent-ref %}


# Control Panel Walkthrough

This section describes each page in the Relay Control Panel (RCP)

## Table of Contents

[Logging in](#to-log-into-the-relay-control-panel)\
[Applying and Undoing changes](#applying-or-undoing-changes)\
[LED indicators](#led-indicators)

#### [Home](#home) [Network Settings](#network-settings) [Relay Settings](#relay-settings) [Relay Family](#relay-family) [Proxy Settings BETA](#proxy-settings-beta) [Change Password](#change-password) [Logs](#logs) [Update](#update)

## Overview

***

### To log into the Relay Control Panel:

1. On your web browser, manually type in the Relay's default hostname <http://relayup.local> or use its local IP.

{% hint style="info" %}

* If <http://relayup.local> is not accessible then you will find the IP of the Relay in your main routers admin interface.
* Open your main router's admin interface (typically accessed via a web browser at <http://192.168.1.1> or <http://192.168.0.1).&#x20>;
* Login using your main router's credentials (usually found on the back of the device).&#x20;
  * Locate the list of connected devices, and find the entry corresponding to your Relay. The IP address listed here is your Relay's LAN IP.
    {% endhint %}

2. On the login page, Type in the default password `admin`.
3. You can now use the Relay Control Panel to configure various settings of your Anyone Relay.

<div align="left"><figure><img src="/files/6nnoUm4cY3MJoh492r0o" alt="" width="563"><figcaption></figcaption></figure></div>

***

### Applying or Undoing changes.

All changes to the Relay require the operator to press **Apply**, then **Save**, and finally **Reboot** to fully implement the changes.&#x20;

To undo any modifications, press <mark style="color:blue;">**Undo Changes**</mark>. This action will revert all changes across all pages.

<figure><img src="/files/ZBKvgTW6Lb1WaEWV7msY" alt="" width="435"><figcaption></figcaption></figure>

***

### LED indicators

<figure><img src="/files/axx64eUHCGWTJFrKBef4" alt="" width="375"><figcaption></figcaption></figure>

Each section of the LED lights in the ANYONE logo has a meaning. Where <mark style="color:green;">Green</mark> indicates 'Connected' or 'Active' and <mark style="color:red;">Red</mark> means Disconnected or Inactive. The logo in the Control panel will always display the status of the LED regardless of it physically pulsing blue or not on the device

***

## Menu

***

### Home

The Home page shows a summarized overview with information and status of the Anyone Router.

<figure><img src="/files/pLEW4Awan0x7wegYOvhg" alt=""><figcaption></figcaption></figure>

#### **Home** page displays in depth information about your Relay, such as:

* **Versions**\
  Displays the version of the Anon client, the backend App, and the frontend Web interface.
* **Reachability**\
  The OR-Port is the port your Anyone relay uses to receive incoming connections from other Anyone Relays. This port must be accessible from the outside to function correctly.&#x20;
* **Flags**\
  These are attributes assigned to Anyone Relays by Directory Authorities. Flags categorize relays based on various criteria. Learn more about flags and their meanings at: <mark style="color:blue;">\<to be added></mark>
* **Fingerprint** \
  This is a unique identifier generated from the Relay's public key, acting as a digital signature that distinguishes your relay from others within the Anyone network.
* **Serial ID**\
  The ID of the device ATEC chip.
* **Public Key**\
  The public key of the device ATEC chip.
* **Board ID**\
  This is the ID of the custom Anyone top board attached to the microcontroller handling various m**anagement and LED control of the device.**
* **Wallet ID**\
  Your specified Ethereum wallet Address.
* **IP addresses**
  * Public IP: The address provided by your internet service provider.
  * Ethernet IP: The address assigned to the Relay by your gateway when connected via Ethernet.
  * Wireless IP: Either the address assigned by your gateway or the address of the Hotspot gateway activated on the Relay. The Hotspot IP is always 10.42.0.1.
  * WLAN1 IP: The address of your external USB WiFi adapter. Which, if available, will always be used to connect to the internet.
* **OS**\
  Operative System running on the hardware.
* **Build date**\
  The date of the installed app version
* **Bootloader**\
  Current bootloader version of top board.
* **Firmware**\
  Current firmware version of top board.
* **Temperature**\
  The Router has two temperature sensors that monitor the environment and current load. The fans activate at 75°C and deactivate at 55°C.

***

### Network Settings

The Network Settings page manages the Anyone Relay's connection to the internet and enables the hotspot for client connections.

<figure><img src="/files/bp9KAZuSzxpoZVaZFx66" alt=""><figcaption></figcaption></figure>

#### **Network** page shows your WiFi Settings and routing options if the Router mode is enabled:

* **Wi-Fi Connect**\
  Displays the SSID and Passkey for connecting to and external network to provide internet to the device.
* **Wi-Fi Hotspot**\
  Displays the SSID and Passkey for the Anyone Hotspot, for anonymous browsing.
* **Routing settings**\
  Set your routing settings to control what region your hotspot clients circuits should use for node connections.
  * GLOBAL
  * APAC
  * EUROPE
  * NORTH AMERICA

***

### Relay Settings

The Relay Settings page manages the Anon client and its settings.

<figure><img src="/files/sQNbw45d6ekw44gGJGAi" alt=""><figcaption></figcaption></figure>

### This page offers a variety of settings to customize your Relay, such as:

**Nickname**\
Set a desired nickname for this relay, the nickname will be public and makes it easier to identify and manage your relays when running multiple.

**Port**\
Set the preferred port for your relay to establish incomming connections on, it is necessary to make sure that the port can be reachable from the Internet and normally requires creating a port forward in your router/gateway.

**Email**\
The email address is optional and can be used if you want to make sure other relay operators have a way to contact you for any reason.

**Wallet ID**\
Set a wallet ID that you own and will use when connecting to the Rewards distribtion protocol dashboard. If you own an [RELAYUP NFT](/resources/token#relayup-nft-phase-2), make sure it is stored on the same wallet address.

**NFT ID**\
Input the NFT ID stored on the wallet that is referenced for this Relay. The NFT must stored on the wallet that is referenced in the Wallet ID field.

**Bandwidth Settings**\
Set the maximum allowed bandwidth rate the Relay is allowed to consume in Mbit/s. Minimum is 2 Mbps and max is 1000 Mbps, which is the max supported speed for this hardware.

**Recurring Data Limit**\
Set the maximum allowed data transfer allowed for a selected period, in days, weeks or months, when the Relay has consumed the defined limit the Relay wil go into hibernation mode and not allow more traffic to be relayed until the period has passed. Mind that the total consumed counter will reset if the Relay is restarted.

**Relay EXE**\
The executable binary of the Anyone client.

**API Call Location**\
The URL of Anyone API for hardware verification to the Rewards Dashboard.

**IP Ping Address**\
Address to check for internet connectivity.

### Factory restore the Relay

<figure><img src="/files/3GHeljXTXC4eiaIFOL66" alt=""><figcaption></figcaption></figure>

To restore the Relay to factory defaults, toggle to **OFF** and check the **Purge** box. Purged Settings can never be restored. This operation will delete:

* Network settings
* Fingerprint
* Logs

***

### Relay Family

The Relay Family page manages declaration of fingerprints of all relays controlled by the same Relay operator.

A Relay operator must declare that this Relay is controlled or administered by a group or organization identical or similar to that of the other relays. Read more about [MyFamily](/sdk/native-sdk/manual#myfamily-fingerprint-fingerprint-1).

The Relay must be toggled to ON in the [Relay Settings](broken://pages/rJYIM8hzDIrNH9HccAob) page to be able to declare fingerprints. Press add and input all the fingerprints of your Relays. When adding the first fingerprints, it will automatically add its own fingerprint on the top line.

<figure><img src="/files/JcuusDmq3H1xgYauDVBo" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/355oj8iTD1GRs5bnEXBU" alt=""><figcaption></figcaption></figure>

Or use the Bulk Import to add several fingerprints at once.

<figure><img src="/files/itOPr685VHDCA8YwMBnS" alt=""><figcaption></figcaption></figure>

To delete multiple fingerprints at once, it is possible to highlight each line by clicking on the fingerprint, then press "**DELETE SELECTED**" and confirm the deletion.

<figure><img src="/files/UdvCym6cJ4hNJIhqWIwt" alt=""><figcaption></figcaption></figure>

***

### Proxy Settings BETA

The Proxy Settings page manages proxy server for the Relay, for clients to connect and route traffic througth the Anyone Network.

<figure><img src="/files/t36nSrVsG91GNw9IFxea" alt=""><figcaption></figcaption></figure>

To enable a proxy server on the **LAN** interface for **Ethernet** or **WiFi**, toggle the sliders to enable or disable the proxy on the desired network interface. The interface must be connected for the proxy server to be available for clients to connect.\
The Relay will set up a proxy server on port **9050** and apply the necessary policies to restrict connections to clients within the same network.

{% hint style="info" %}
To learn how to Connect to the Proxy, see the "[Connecting to the Network](/connect/apps)" page for a detailed guide on some common applications.
{% endhint %}

***

### Change Password

<figure><img src="/files/QiokKrT50SmC9J5JtJay" alt=""><figcaption></figcaption></figure>

The Change Password page allows the operator to change the password for accessing the Relay Control Panel. The password can be up to 32 characters long.&#x20;

The following characters are not allowed `#`, `'`, `\`, `=`, `´`, `*`.

***

### Logs

The Logs page displays necessary information about the Anyone Relay.

<figure><img src="/files/l2GohUk1j1kQjhuCUBM3" alt=""><figcaption></figcaption></figure>

The **Logs** section provides detailed system logs that are essential for troubleshooting and monitoring the Relay's activity.&#x20;

Users can access various log files, such as:

* **notices.log**\
  This file records the Anyone network's initialization process, detailing the steps involved in connecting to the network, downloading configuration data, and establishing anonymous connections. It is crucial for troubleshooting connection issues and understanding the behavior of the Anyone client.
* **00\_logs.log**\
  This log captures the output generated when the app handles backend changes. It is essential for troubleshooting and contains messages or errors that may occur while operating the Relay.
* **bootstrap.log**\
  This log captures output during the initial installation and setup of the operating system, specifically during the bootstrapping process. It typically contains messages related to package installations, configurations, and any errors or issues encountered during system startup.

***

### Update

<figure><img src="/files/yfnp1t0xm7gdjCzutpvX" alt=""><figcaption></figcaption></figure>

The **Update** page enables the operator to update both the **app** and **web files** of the Relay directly through the **Control Panel**.

For future updates, compatible update files will be provided, ensuring seamless upgrades and improved functionality. It is recommended to regularly check the **Update** page for the latest versions to maintain security, stability, and access to new features.


# Hardware-specific Updates

{% content-ref url="/pages/Az3U2m1WrNmkakQTuy2H" %}
[System Update (USB)](/hardware/hw-updates/update)
{% endcontent-ref %}

{% content-ref url="/pages/tVfH5ui3X2n0Ro3oSBgG" %}
[System Update (WebUI)](/hardware/hw-updates/update-ui)
{% endcontent-ref %}

{% content-ref url="/pages/pmu3adxMbwRm6E6YUrj1" %}
[Anon Update (WebUI)](/hardware/hw-updates/update-anon)
{% endcontent-ref %}


# System Update (USB)

This page will guide you on how to update your Relay using a USB stick. This update introduces Router Mode, a reworked Setup Wizard and more.

### What's new? <a href="#whats-new-in-version-1.3.2" id="whats-new-in-version-1.3.2"></a>

### In the versions APP 2.0.6 and WEB 3.2.0:  <a href="#whats-new-in-version-1.3.2" id="whats-new-in-version-1.3.2"></a>

* **The Relay now supports Router mode:** When Router mode is enabled and when a user is connected to the hotspot, their traffic will be automatically routed through the Anyone Network and provide seamless privacy. Router mode has replaces Hotspot Proxy function from previous versions.
* **Mode selection:** Gives the operator the option to configure the hardware as a Relay Only, Relay and Router combo, or Router Only when using the Setup Wizard that is initiated by holding the physical blue button for 3 seconds.
* **Update via WEB UI:** This version support updating the Relay by going to 'System > Update' and selecting update files. Future updates will use this method.
* **Adding MyFamily in bulk:** Paste a set of fingerprints as a comma separated list or line by line in one go for a quicker MyFamily configuration. In addition, the limit on 90 fingerprints has been removed.
* **Support for the extra WiFi USB dongle** shipped with the latest Relay batches, this allows the Relay to use a Wireless connection joining a Local Network as well as having a Hotspot enabled at the same time.
* **Setup Wizard:** To provide a more intuitive experience when performing the initial setup of the Relay, our focus for this update has been on the setup wizard, with minor changes to the Relay Control Panel.
* On the [**Relay Settings**](broken://pages/rJYIM8hzDIrNH9HccAob) page, the **Bandwidth Settings** feature now uses the parameters **RelayBandwidthBurst/RelayBandwidthRate** instead for **BandwidthBurst/BandwidthRate**. The latter restricts all traffic including client traffic which is not suitable with the introduction of the Router Mode. See the [Anon Manual](/sdk/native-sdk/manual) for reference.
* Optimisations to reduce the CPU and Memory resources consumed by the APP.
* Improved validation on files uploaded via Relay Control Panel.
* While relay was in '**Relay-Router**' mode, the title in the RCP displayed '**Router**' with unsaved changes.
* Added PEAQ integration, read more about it over at [Medium](https://anyone-protocol.medium.com/3a307ecabdff).

***

### Update prerequisites:

* The relay has to be on **APP** version **2.0.0** or above for this update to run successfully. Verify the version on the Home page of the Relay Control Panel.
* This update method **requires** a USB memory stick.
* The files from this update can **not** be used to update from the RCP using the update page.

### How to update: <a href="#how-to-update" id="how-to-update"></a>

1. Grab any USB drive and plug it into your computer, ensure the filesystem on the USB drive is FAT or FAT32. <br>
2. Download both **default.cfg** and **update.zip** and place on the USB drive, make sure the files are **NOT** renamed or unpacked, the files names must be exactly **default.cfg** and **update.zip** even after download.

{% hint style="warning" %}
Only if you have changed the default password for the Relay Control Panel, then open the file **default.cfg** with any editor and change the first line "**`01_user_password=MyPassword`**" to include your password.
{% endhint %}

{% file src="/files/kifEKn0iyoR34T0sFSva" %}

{% file src="/files/FFYBitjJ1GPWxjbgSrtv" %}

3. Plug in the USB to your Relay and unplug when the LED's are <mark style="color:green;">**flashing in green**</mark>, the relay will restart when USB is unplugged. Wait for the Relay to start up again.

{% hint style="warning" %}

* If the lights of the relay flashes in <mark style="color:red;">**Red**</mark>, it means the password is wrong in default.cfg, readd default.cfg and correct the password.
* If the lights of the relay flashes in <mark style="color:blue;">**Blue**</mark>, it means the files have not been placed properly, delete all files from the USB and re-add them again.
  {% endhint %}

4. When relay has restarted you can login to the [Relay Control Panel](http://relayup.local) and verify that you see the latest version as shown below, located in the **Versions** and **Identification** section on the **Home** page.

<div align="left"><figure><img src="/files/9KFp3R7k9Fns9xfBC9DZ" alt="" width="491"><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/Hl72pGyXvWkEqrYgPTU8" alt="" width="495"><figcaption></figcaption></figure></div>

5. (**Optional**). To change the modes, press the physical <mark style="color:blue;">**blue**</mark> button located on your Relay for 3 seconds, connect to the wireless network named '**relayup\_XXXXXX**' and follow the instructions on the captive portal.

### You´re done! <a href="#you-re-done" id="you-re-done"></a>

Visit our [Support Page](/resources/support) for any questions.


# System Update (WebUI)

This page will guide you on how to update your Relay using via the RCP. This update requires the Relay to be on APP version 2.0.6.

### Do <mark style="color:red;">**NOT**</mark> use this update method unless the relay is already on **APP** version **2.0.6 or above,** <mark style="color:red;">trying will break the relay</mark>. See [System Update (USB)](/hardware/hw-updates/update) if on a lower version.

### Update prerequisites:

* Requires APP version 2.0.6 or above.
* This update is performed in 2 stages with 2 different files from within the Relay Control Panel (RCP), and does **not** require a USB memory stick.
* Do not rename the downloaded files and do not unpack the .zip archives.

### Change log:

* Improved validation on files uploaded via Relay Control Panel
* While relay was in '**Relay-Router**' mode, the title in the RCP displayed '**Router**' with unsaved changes.
* Added PEAQ integration, read more about it over at [Medium](https://anyone-protocol.medium.com/3a307ecabdff).
* This update only updates the WEB to **WEB 3.2.0.**

### How to update:

1. Download '**app-update\_php\_v1.zip'** from below.

{% file src="/files/2BBbvXD2vz4S8MSB1KsB" %}

2. Login to the Relay Control Panel and navigate to **System** > **Update**.
3. Upload downloaded file to the Relay by dragging and dropping, alternatively press inside the box to browse for the file you just downloaded. Then press the '**UPLOAD FILES**' button.

<div align="left"><figure><img src="/files/RbsnXi6kOgcrXFSGSmPm" alt="" width="563"><figcaption></figcaption></figure></div>

4. Enter your RCP password to confirm the upload.

<div align="left"><figure><img src="/files/IfD3tG8FlFwfxiWyM3Se" alt="" width="563"><figcaption></figcaption></figure></div>

5. Press the '**REBOOT**' button.

<div align="left"><figure><img src="/files/qhuRwXhsASzycCKw3yFB" alt="" width="563"><figcaption></figcaption></figure></div>

6. While waiting for the Relay to restart, download the file '**app-update\_peaq\_v1.zip**' from below, then repeat steps **2** to **5** while using this file instead.

{% file src="/files/96dDG2w3RNJpNCv8XgDo" %}

7. To verify that the update was successful you should see '**Web 3.2.0**' in the **Versions** box, and the added '**PEAQ Identifiers**' in the **Identifications** box, as shown below.

<div align="left"><figure><img src="/files/9KFp3R7k9Fns9xfBC9DZ" alt="" width="327"><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/Hl72pGyXvWkEqrYgPTU8" alt="" width="330"><figcaption></figcaption></figure></div>


# Anon Update (WebUI)

How to Update the Anon Service on the Hardware Relay

The Anon version running on your device can be seen on the [**Home**](broken://pages/r6k1tGqfNcH1CtHH9oAz) page under **Versions**.

<div align="left"><figure><img src="/files/Y1s9CbDRn0UNuFFILTJo" alt="" width="308"><figcaption></figcaption></figure></div>

Once in a while the Anon packages are being updated and updates don't happen automatically on hardware devices.

Latest "live" version of Anon can be seen on GitHub Releases or in the Anyone repository.\
<https://github.com/anyone-protocol/ator-protocol/releases>\
<https://deb.en.anyone.tech/pool/main/a/anon/>

### Trigger the System to Update Anon

When the relay is turned OFF and ON again it will be triggered to look for and install the latest version of the Anon package.

Go to the [**Relay Settings**](broken://pages/rJYIM8hzDIrNH9HccAob) page in the control panel to turn OFF the relay function.

1. Toggle the **ON/OFF** button to the **OFF** position.
2. Click **APPLY**.
3. Click **SAVE** (<mark style="color:red;">make sure you do</mark> <mark style="color:red;"></mark><mark style="color:red;">**NOT**</mark> <mark style="color:red;"></mark><mark style="color:red;">tick the</mark> [Purge](broken://pages/rJYIM8hzDIrNH9HccAob#factory-restore-the-relay) <mark style="color:red;">box</mark>).
4. **REBOOT** the device to apply the change.

<div align="left"><figure><img src="/files/i6Ooa9iR6D5pICOpNvHB" alt="" width="563"><figcaption></figcaption></figure></div>

Now, repeat the same steps to turn it back **ON.**

6. Toggle the **ON/OFF** button to the **ON** position.
7. Click **APPLY**.
8. Click **SAVE** again.
9. **REBOOT** the device one more time.

<div align="left"><figure><img src="/files/hVWUxL6nJXjlCyMKphID" alt="" width="563"><figcaption><p>Follow steps .. 6, 7, 8, 9</p></figcaption></figure></div>

{% hint style="info" %}
Operators will be able to update the service from a simplified setting in later versions of the Web UI.
{% endhint %}


# Hardware Troubleshooting

{% content-ref url="/pages/VyLxcfV8L1r8pkAuypx2" %}
[Router Port Forwarding](/hardware/troubleshooting/router-port-forwarding)
{% endcontent-ref %}

{% content-ref url="/pages/3Xjo7D2dq7IGA6PCHkl6" %}
[Diagnosing CGNAT and Public IPv4](/hardware/troubleshooting/diagnosing-cgnat-and-public-ipv4)
{% endcontent-ref %}


# Router Port Forwarding

Port forwarding is a necessary step in setting up a Anyone Relay, allowing external connections to reach your relay's designated port (default: 9001). This universal guide covers the port forwarding process applicable to most routers. It's important to note that while the default port is 9001, you can optionally choose another port.

{% embed url="<https://youtu.be/J5WEC8USsVQ>" %}

### 1.   Access Your Router's Settings

In this step we provide examples for different Operating System's on how to get your routers IP-address to access its settings. The IP-address of a router may differ but is typically something like: `192.168.x.x` or `10.x.x.x`.

**If you already know how to access your router's settings then you can skip to** [**next step**](#id-2.-locate-the-port-forwarding-section-in-your-routers-control-panel)**.**

{% tabs %}
{% tab title="Windows" %}

1. **Open Command Prompt**

Press `Win + R`, type `cmd`, and press Enter to open the Command Prompt.

2. **Run `ipconfig`**

Type `ipconfig` and press Enter. Look for the "Default Gateway" entry under the active network connection.

**Identify Router IP**

```
Default Gateway . . . . . . . . . : 192.168.1.1
```

{% endtab %}

{% tab title="macOS" %}

1. **Search for and open the 'terminal.app' application.**
2. **Copy and paste the below commands in full in the terminal.**

{% code fullWidth="false" %}

```sh
route -n get 'default' | grep 'gateway'
```

{% endcode %}

<div align="left"><figure><img src="/files/CRkzgdfbBGvKzsfPCtA9" alt=""><figcaption></figcaption></figure></div>

In this example, the output of the commands show that the IP-address of the router is **`10.211.57.1`**. This is the IP-address to open a browser to access router settings.
{% endtab %}

{% tab title="Linux" %}

1. **Search for and open the 'terminal' application.**
2. **Copy and paste the below commands in full in the terminal.**

```sh
ip route | grep default | cut -d " " -f1-3
```

In this example, the output of the commands show that the IP-address of the router is **`10.211.56.1`**. This is the IP-address to open a browser to access router settings.
{% endtab %}
{% endtabs %}

### **Open Your Web Browser**

Now open any web browser and paste the IP-address of the router that you looked up in the previous step.

#### **Login to the Router**

Enter your router's username and password. If you haven't changed these, check your router documentation or on the back label, for default credentials.

### 2.   Locate the Port Forwarding Section in your Routers Control Panel

#### **Navigate to Port Forwarding**

Look for a section named "**Port Forwarding**" in your router settings. The location may vary but is often found under the "Advanced" or "Security" tab.

#### **Choose a Device**

Select the device running your Anyone Relay from the list of connected devices.

### 3. Configure Port Forwarding

**a.   Add a New Rule**\
Create a new port forwarding rule.\
\
b.   **Specify Port**\
Enter the port number \
Default is normally 9001 otherwise specify your chosen port in the required fields.\
\
c.   **Select Protocol**\
Choose "TCP/UDP" as the protocol.\
\
d.   **Set IP Address**\
Enter the local IP address of your Anyone Relay device. You can find this in your device's network settings.\
\
e.   **Leave source IP empty**\
Do not enter anything in the field for source IP to ensure anyone on the network can connect to your relay on the specified port.

#### Save your settings, and if required, reboot your network router or firewall.

### 4.   Verify Port Forwarding

#### **Use Online Tools**

Utilize online tools like "CanYouSeeMe.org" to check if your specified port is open.

Make sure your Anyone Relay is configured to use the forwarded port. \
Update the anonrc file with the chosen port accordingly.

```bash
ORPort <YourChosenPort>
```

### 5.   Security Considerations

#### **Use Strong Passwords**

Make sure your router login credentials and Anyone Relay are secured with strong, unique passwords.

\
**Regularly Monitor Activity**

Periodically check router logs for any unauthorized access and monitor your relay's performance.

***

### External Resources

For router-specific instructions or troubleshooting, refer to your router's manual or visit the manufacturer's website. Below are links to guides for some popular router brands:

* [Linksys Port Forwarding Guide](https://www.linksys.com/support-article?articleNum=138535)
* [Netgear Port Forwarding Guide](https://kb.netgear.com/24289/How-do-I-set-up-port-forwarding-to-a-local-server-on-my-NETGEAR-router)
* [TP-Link Port Forwarding Guide](https://www.tp-link.com/us/support/faq/1379/)
* [D-Link Port Forwarding Guide](https://www2.dlink.com/us/en/support/faq/routers/mydlink-routers/dir-605l/how-do-i-configure-port-forwarding-on-my-router)
* [Asus Port Forwarding Guide](https://www.asus.com/support/FAQ/1037906/)

Remember that the steps may vary slightly based on different router models. Always prioritize security and consult your router's documentation for model-specific details.\
\
If you can't find your router in the list above, try finding it in this archive:\
<https://portforward.com/router.htm>\
(no need to install any network utilities)


# Diagnosing CGNAT and Public IPv4

### What is CGNAT?

Carrier-Grade Network Address Translation (CGNAT) is a technique used by Internet Service Providers (ISPs) to deal with the shortage of available IPv4 addresses. In a CGNAT environment, multiple customers share a single public IPv4 address, hindering the ability to directly forward ports to devices within a network.

### Diagnosing CGNAT

#### **Check Your Router's WAN IP:**

* Log in to your router and locate the **WAN IP** address. If it's a private IP address (e.g., 10.x.x.x, 100.x.x.x, 192.168.x.x,), your network is likely behind a CGNAT.
* Check if your routers **WAN IP** matches the **IP address** on [browserleaks.com/ip](https://browserleaks.com/ip), if the IP's does not match then you can be certain CGNat is enabled for your Internet service.

**Check with Your ISP:**

* Contact your Internet Service Provider and inquire about your IP address type. If they confirm it's a private IP, you're likely under CGNAT.

### Dealing with CGNAT

**Contacting Your ISP Requesting a Dynamic Public IP:**

* Inform your ISP about the port forwarding needs.
* Request a dynamic public IP address to enable you to forward ports.
* Some ISP's charge extra for a static IP if the ISP can't help you with a dynamic IP.


# Security and Privacy

{% content-ref url="/pages/XJ5YL6jEA5UdWMx60HFI" %}
[VPS Hardening & Best Practices](/relay/vps-hardening-and-best-practices)
{% endcontent-ref %}


# Anyone Bug Bounty Program

The Anyone Bug Bounty program is now live! Here, you can find each competition track, the prizes, starting information and other conditions. For more context on the Bug Bounty contest, check out our [Medium Article](https://anyone-protocol.medium.com/the-anyone-bug-bounty-program-c31e3e2a493c).&#x20;

{% hint style="success" %}
**Submitting your success proofs**

To ensure anonymity of participants and broaden ecosystem use-case, you submit your bug bounty proofs via a form in a dedicated **hidden service** in the Anyone Network. To access, fire up the Anyone client and go to the below page:\
<http://2sx274i4dadq3ijo27lj55xi5q7paodkfq6g5mi4jz57dt2nztpqmdad.anon>&#x20;
{% endhint %}

## Competition Tracks

#### Code Archaeology (Easy)

**Target:** Anyone public repositories and commit history.\
**Objective:** Find leaked secrets/tokens/credentials from Anyone’s GitHub account.\
**Success proof:**\
— Link to the commit/file,\
— Show it’s not cycled and is still active,\
— Show it was accessible outside the org (e.g., your Action run).\ <mark style="color:orange;">**Bounty:**</mark> <mark style="color:orange;">**A hardware relay**</mark> <mark style="color:orange;"></mark><mark style="color:orange;">given for each of the first 10 unique secrets.</mark>\ <mark style="color:blue;">**Starting Info:**</mark> Use our GitHub organization <https://github.com/anyone-protocol>

#### Operations Chamber (Medium)

**Target**: Ops UI endpoint\
**Objectives**:

* Bypass oauth2\_proxy without valid creds
* Access services you shouldn’t be able to
* Escalate read-only to write if possible

**Success proof**: Screenshot of unauthorized access and HTTP logs of your requests.\ <mark style="color:orange;">**Bounty**</mark><mark style="color:orange;">:</mark> <mark style="color:orange;"></mark><mark style="color:orange;">**2000 tokens**</mark> <mark style="color:orange;"></mark><mark style="color:orange;">for each of first 3 unique exploits.</mark>\ <mark style="color:blue;">**Starting Info**</mark>: Target the ops endpoint at  (`*.ops.anyone.tech`)

#### Process Hijack: AO Protocol (Hard)

**Target:** Staging AO processes (relay/staking/operator registry).\
**Objective:** Perform unauthorized write ops or escalate privileges from read-only.\
**Success proof:** Process transaction ID and method documentation.\ <mark style="color:orange;">**Bounty:**</mark> <mark style="color:orange;">**5000 tokens**</mark> <mark style="color:orange;"></mark><mark style="color:orange;">for each of the first 3 unique exploits.</mark>\ <mark style="color:blue;">**Starting Info**</mark>: Attempt to compromise the below AO processes

* `GDcOVcu5FQk5oYYC_fDxDzOpiKRFLpOqoIxF9ATTAjc`
* `AQIxBWYFpyplmKnl72UkXGgTZAPXBKPuQsDQ9O45bZ0`
* `XJQw0fL7HB0Uclcn6tAxLXjjqFSSZgNiSlpy96unxbk`

#### Hodler's Vault: EVM Smart Contracts (Hard)

**Target:** Staging Hodler contract (address will be provided).\
**Objective:**

* Drain funds,
* Manipulate state, reentrancy, or any critical vulnerability

**Success proof:** Transaction hash on staging and detailed exploit writeup.\ <mark style="color:orange;">**Bounty:**</mark> <mark style="color:orange;">**10,000 USDT.**</mark>\ <mark style="color:blue;">**Starting Info**</mark>: Focus on the following Sepolia smart contract:

* `0xB2B365DC481E9527366b29dE9394663A05743Aa9`

#### Walls of Anyone: Server Boundaries (Very Hard)

**Target**: Break into a designated dev-box with reference setup\
**Objective**:

* Gain unauthorized SSH access, or
* Bypass firewall rules
* Privilege escalation to `root` role

**Success proof**: Generate a syslog entry: `CTF_FLAG_FORTRESS_[your_pubkey]_[timestamp]`\ <mark style="color:orange;">**Bounty:**</mark> <mark style="color:orange;">**20,000 USDT.**</mark>\ <mark style="color:blue;">**Starting Info**</mark>: We have made public the IP address of the server:

* `95.216.68.239`

## Rules and Scope

### In Scope:

1. **Servers:**\
   \- Operating System\
   \- SSH\
   \- Firewall\
   \- WireGuard interface
2. **Mesh Endpoints:**\
   \- oauth2\
   \- Grafana\
   \- Network information services
3. **GitHub:**\
   \- Public repositories\
   \- Commit history\
   \- GitHub Actions configs / CI/CD
4. **Blockchain:**\
   AO processes:\
   \- *Relay rewards*\
   \- *Staking rewards*\
   \- *Operator registry*

### Out of Scope

1. **Resources:**

   **-** Production/live infra,\
   \- Team member personal accounts/emails,\
   \- Community member data, any endpoints not listed here\
   \- Live/mainnet contracts or processes.
2. **Techniques:**

   \- DDoS/resource exhaustion,\
   \- Phishing team or community,\
   \- Access/modify other participants’ submissions,\
   \- Modify/delete data (proving you could is enough),\
   \- Publish details before fixes or before the program ends.\
   \- Utilizing zero-day bugs to pass challenges.

### ⏰ Challenge Deadline:

The deadline to submit to the bug bounty program is **19th November 2025.** Good luck to all participants!&#x20;


# Submissions Round 1

Thank you for the first round of submissions! As part of our commitment to transparency, we will be sharing bug-finding attempts here (where no additional risk is posed) alongside our response and/or mediation.&#x20;

Participants' identity will be anonymized. Submissions made here will also disqualify identical submissions made afterwards.&#x20;

#### Submission 1 | Track 1&#x20;

**Leaked API Keys in API Service Respository**\
Evidence of two exposed API keys found in the commit history of api-service. Auto-detected by Gitleaks on a local VPS. \
**Response**: Negative – misinterpretation of strings

**Hard-coded JWT for Airdrop values in Dashboard**\
Hard-coded JWT tokens and API-like keys in nuxt.config.ts for Supabase.\
**Response:** Not a secrets leakage as it has the *`anon`* service role and points to public data. However, this JWT could be stored as a deploy secret, good find!

**Unnecessary private key and certificate included in test data**\
Ran Gitleaks full-history scan. Repository: anyone-protocol/sbws.\
**Response:** Negative. We accept tests working out of the box with the same keys.

**Private TLS key included in test directory**\
Ran Gitleaks full-history scan. Detected PEM format private key. \ <mark style="color:blue;">**Response:**</mark> Negative. We accept tests working out of the box with the same keys.

**Leaked private signing keys inside Docker example directories**\
Ran Gitleaks full-history scan. Detected PEM format keys in Docker example directories.  \ <mark style="color:blue;">**Response:**</mark> Negative. We accept tests working out of the box with the same keys.

#### Submission 2 | Track 2

**Publicly reachable service at** [**containers.ops.anyone.tech**](http://containers.ops.anyone.tech)\
Passive reconnaissance scan of \*.[ops.anyone.tech](http://ops.anyone.tech) to collect HTTP status codes and final redirect targets.\ <mark style="color:blue;">**Response**</mark><mark style="color:blue;">:</mark> The containers are inherently setup as public. This track would have looked for a bypass of the oauth\_proxy.&#x20;

**CORS misconfiguration on api.ec.anyone.tech**\
During passive recon of public Anyone endpoints discovered via crt.sh, exposing a wildcard CORS policy. \ <mark style="color:blue;">**Response:**</mark> Setup for the use by certain services, but this is not ideal practice. Needs review.

<mark style="color:$success;">**Prize:**</mark> While this attempt did not strictly find a high-risk vulnerability, this was a thorough attempt making use of Gitleaks. The submitter will be contacted to receive a small prize!

#### Submission 3 | Track 1

**Leaked APIKey of Supabase**\
Manual repository review, found API key that allows public query\
**Response:** Not a secrets leakage as it has the *`anon`* service role and points to public data. However, this JWT could be stored as a deploy secret, good find as above!


# Rewards Dashboard

### The only official URL to the Anyone Protocol & Staking Dashboard is:

#### [**https://dashboard.anyone.io**](https://dashboard.anyone.io/)

### Using the Anyone Protocol & Staking Dashboard:

{% embed url="<https://www.youtube.com/watch?v=UD6bdwwo2jY>" %}

[00:00](https://www.youtube.com/watch?v=UD6bdwwo2jY) Introduction \
[00:34](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=34s) Introducing the homepage \
[00:54](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=54s) Connect wallet \
[01:10](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=70s) Introducing the relays page \
[01:26](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=86s) Locking a regular relay \
[02:00](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=120s) Claiming a regular relay \
[02:37](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=157s) Claiming a hardware relay \
[03:05](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=185s) Delegating locks \
[03:33](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=213s) Introducing the staking page \
[04:40](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=280s) Staking tokens \
[05:28](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=328s) Unstaking \
[05:54](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=354s) Unlocking and Renouncing \
[06:35](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=395s) Claiming rewards \
[07:47](https://www.youtube.com/watch?v=UD6bdwwo2jY\&t=467s) Withdrawing back to your wallet

### Written Guide

<table data-card-size="large" data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/HOIqKCSwQda5LU1TR66Q">/pages/HOIqKCSwQda5LU1TR66Q</a></td><td><h4>Follow the steps to make sure your relays are correctly registered.</h4></td><td><a href="/files/MhEiaT6OK6GWByulceKb">/files/MhEiaT6OK6GWByulceKb</a></td></tr><tr><td><a href="/pages/rhCcL6zm8kH4vyJeYwR7">/pages/rhCcL6zm8kH4vyJeYwR7</a></td><td><h4> Learn how to connect and navigate the decentralized dashboard.</h4></td><td><a href="/files/1gJUEi9zRNDcly6wzXNX">/files/1gJUEi9zRNDcly6wzXNX</a></td></tr></tbody></table>

<table data-card-size="large" data-view="cards" data-full-width="false"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><a href="/pages/rzaj1EhYJapqiHCfVmPD">/pages/rzaj1EhYJapqiHCfVmPD</a></td><td><h4>Understand how to monitor rewards, claim tokens, and manage your relay operations.</h4></td><td><a href="/files/hPHti7rs98DgEs6uIhw3">/files/hPHti7rs98DgEs6uIhw3</a></td></tr><tr><td><a href="/pages/cLvDXm1lonrFoKmllU5T">/pages/cLvDXm1lonrFoKmllU5T</a></td><td><h4>Understand how rewards are currently emitted and on what criteria.</h4></td><td><a href="/files/EI1shrUnfyn28Gb7K8xV">/files/EI1shrUnfyn28Gb7K8xV</a></td></tr></tbody></table>


# Registering Relays

To register your relay and begin earning rewards, follow these steps to set up your machine and complete the registration process on the [Anyone Protocol Dashboard](/dashboard/access).&#x20;

If you have a [**Anyone Hardware Relay**](/hardware/overview), you do not need to lock tokens—simply [claim](/dashboard/use#claim-relays) the device once it's set up.&#x20;

***

#### Contents of this page:

[**Installation and Configuration**](/dashboard/register#installation-and-configuration)

[**Adding Ethereum Wallet Address to anonrc**](/dashboard/register#adding-ethereum-wallet-address)

[**Using the Dashboard to Claim and Manage Your Relays**](/dashboard/register#using-the-dashboard-to-claim-and-manage-your-relays)

***

## **Installation and Configuration**

1. **Install the Anon package** and configure your relay.

{% hint style="info" %}

### <mark style="color:blue;">**Anyone Hardware devices**</mark>

***

Follow the instructions provided in the **Hardware** section, Setup Guide or Relay Settings to enter your Ethereum Address.\
\
Anyone Hardware relay Setup Wizard:\
:link: [Hardware Setup](/hardware) > :link: [Setup Guide](/hardware/setup-guides/relay-mode)\
\
To manually edit the address and NFT info in the Control panel visit:

:link: [Hardware Setup](/hardware) > :link: [Relay Control Panel](broken://pages/rJYIM8hzDIrNH9HccAob) > :link: [Relay Settings](broken://pages/rJYIM8hzDIrNH9HccAob)
{% endhint %}

{% hint style="info" %}

### <mark style="color:blue;">**Standalone devices**</mark>

***

Follow the instructions provided in the **Installation** section to get started setting up a relay and configure your <br>

:link: [Relay Setup](/relay) > :link: [Installation and Usage](/relay/start) > :link: [Setting up Your Environment](/relay/start/prep)

\
If you already have a relay running, continue reading!
{% endhint %}

## **Adding Ethereum Wallet Address**

2. **Add your wallet address** to the anonrc file to link it with your relay for rewards.

Debian example: Open the anonrc file in a text editor:

```bash
sudo nano /etc/anon/anonrc
```

Find the `ContactInfo` line, and add your wallet address with the prefix `@anon:` .&#x20;

{% code title="Example" %}

```
ContactInfo @anon: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
```

{% endcode %}

3. Restart the Anon service to apply the changes:

```bash
sudo systemctl restart anon.service
```

***

{% hint style="info" %}

### **Optionally Verify the Changes in anonrc**

`sudo /usr/bin/anon -f /etc/anon/anonrc --verify-config`
{% endhint %}

## Using the Dashboard to Claim and Manage Your Relays

Once your machine is set up, follow these steps to connect your wallet, lock tokens (if necessary), and claim your relay via the **Anyone Protocol Dashboard**.

{% content-ref url="/pages/rzaj1EhYJapqiHCfVmPD" %}
[Using Dashboard](/dashboard/use)
{% endcontent-ref %}

(Note that it can take a few hours for the device to show up on the dashboard after registering the address in the configuration of your relay)

{% hint style="info" %}
See :link: [Resources](broken://pages/qwk6iHoeoj4H46mnPjyE) & :link: [Community and Customer Support](/resources/support) for help and updates.
{% endhint %}

{% hint style="success" %}
![](/files/DDTnxicC3iMfTqtJLFqp)

### [See full video tutorial on the Rewards Dashboard page.](/dashboard)

{% endhint %}


# Accessing Dashboard

***

### Loading the Dashboard

The decentralized nature of the Anyone Dashboard means that **there is no server** providing data to the dashboard. Instead, the most up-to-date state is calculated on the client side (on the users' computer) using a local 'worker'. This worker aggregates the newest set of Arweave distribution data for the relays to calculate the latest scores.

This means that there is a slightly longer loading time when opening the dashboard for the first time or when a wallet has many relays. This also means that it is recommended to interact with the Anyone dashboard from a laptop or desktop, as opposed to a mobile browser.&#x20;

Censorship resistance is more than a buzzword for the protocol - we are proud to host the most censorship resistant and decentralized dashboard in all of DePIN!&#x20;

### The only official URL to the Anyone Protocol & Staking Dashboard is:

#### [**https://dashboard.anyone.io**](https://dashboard.anyone.io/)<br>

{% hint style="success" %} <img src="/files/3F34lfUhwCKscL6hPBHx" alt="" data-size="original">

### [See full video tutorial on the Rewards Dashboard page](/dashboard)

{% endhint %}


# Using Dashboard

This guide will help you navigate the Anyone Protocol Rewards Dashboard and manage your relay operations. On this page you will find the actions you can perform, with detailed instructions.

#### Contents of this page:

[Connecting EVM Wallet](#connecting-evm-wallet)

[Locking Anyone Tokens](#locking-anyone-tokens) - (**Not** required for [Anyone Hardware Relays](https://www.anyone.io/hardware))

[Claim Registered Relays](#claim-registered-relays)

[Redeem Contribution Rewards](#redeem-contribution-rewards)

[Renounce Claimed Relays](#renounce-claimed-relays)

## Connecting EVM Wallet

#### Connect your Ethereum wallet to the dashboard.

1. Ensure that your wallet is connected to Ethereum Mainnet, which comes as a default setting in most wallets  (see [Status & Term History](/dashboard/status) for information on mainnet $ANYONE rewards).
2. Open the [Anyone Protocol Dashboard](/dashboard/access) in your browser.
3. Click **Connect Wallet** in the top-right corner.
4. Choose your wallet provider (e.g. MetaMask).
5. Follow the prompts to authorize the connection.

<div align="left" data-full-width="false"><figure><img src="/files/U8lAfFfA0VdxAF1nrWah" alt=""><figcaption><p>Connect EVM wallet to the dashboard</p></figcaption></figure></div>

Once connected, after a brief loading period, relay information will be accessible from the dashboard's **Relay** tab.&#x20;

***

## Locking Anyone Tokens

{% hint style="success" %}
This step is **not** required for [Anyone Hardware Relays](https://www.anyone.io/hardware).\
[Continue to 'Claim Registered Relays'..](#claim-registered-relays)
{% endhint %}

{% hint style="danger" %}
Delegated Locking\
We have revamped the delegated lock to remove the risk of manipulation and add a layer of privacy. These locks works on the protocol level but will not show up by default on the dashboard. Look out for an announcement shortly on how this mechanism works!
{% endhint %}

1. Under both **Relays > All Relays** and **Claimable Relays**, \
   you'll find to the "**Lock 100 $ANYONE"** button.
2. Proceed by locking the relays you wish to [claim](#claim-registered-relays).
3. Confirm the transactions using your wallet. There will be two interactions.
   * Spending Cap Request and,
   * Send and lock 100 $ANYONE.

<div align="left"><figure><img src="/files/eSDe4rE8mLIkx0JdBIo9" alt=""><figcaption><p>Locking $ANYONE tokens</p></figcaption></figure></div>

Once completed, your relays will be eligible to claim.

***

## Claim Registered Relays

#### Once validated through a lock or with a Hardware relay, you can claim your relays to start redeeming your rewards

1. In the **Relays** section of the dashboard, select the relays you wish to claim.
2. Confirm the action by signing the authentication with your wallet.

Claim Anyone Hardware Relay:

<div align="left"><figure><img src="/files/LV5V2eQHGMPMtNCZwbTe" alt=""><figcaption><p>Claim Anyone Hardware Relay</p></figcaption></figure></div>

Claim Regular Relay:

<div align="left"><figure><img src="/files/LOIRgEhMw1snH8jCeH7i" alt=""><figcaption><p>Claim Regular Relay</p></figcaption></figure></div>

{% hint style="info" %}
**Note:** \
Sometimes the signature request displays the message in wrong format.\
This is a bug that will be investigated and fixed in future versions of the dashboard.
{% endhint %}

<div align="center"><figure><img src="/files/czDv0iNvtPjADSlibXn5" alt="" width="320"><figcaption></figcaption></figure> <figure><img src="/files/4BI6q3pu96YOCMtvyOAX" alt="" width="292"><figcaption></figcaption></figure></div>

Your relays are now claimed and registered. You’ll be accumulating rewards over time.\
\
Come back to the dashboard again, later, and [Redeem some rewards](#redeem-contribution-rewards)..

***

## Redeem Contribution Rewards

#### To redeem your accumulated rewards, go to the Home page of the Dashboard

1. You’ll see the total $ANYONE tokens available for redemption.
2. Click the Redeem Rewards button and confirm the transaction using your wallet.
3. Rewards will be added to your **Available** balance on the dashboard.&#x20;

<div align="left"><figure><img src="/files/aYw45JQ72zfCcJVOd6dH" alt=""><figcaption><p>Redeem $ANYONE tokens</p></figcaption></figure></div>

***

## Renounce Claimed Relays

If you want to migrate a fingerprint to another wallet, first change the wallet for the relay, then follow these steps.

1. Select the fingerprint, click on the three dots next to it, and choose **Renounce.**

<div align="left"><figure><img src="/files/dlkzPKaXEno0DpqSXBzU" alt="" width="188"><figcaption></figcaption></figure></div>

2. Sign the two transactions. These transactions do not require any gas fees.

<div align="left"><figure><img src="/files/RryS4xFAirPOxERPINIj" alt="" width="170"><figcaption></figcaption></figure></div>

The claimed fingerprint will show a loading animation and then disappear from the dashboard.

<div align="left"><figure><img src="/files/ElFh0kYzemUMiCrq1bhx" alt="" width="134"><figcaption></figcaption></figure></div>

{% hint style="success" %}
![](/files/DDTnxicC3iMfTqtJLFqp)

### [See full video tutorial on the Rewards Dashboard page.](/dashboard)

{% endhint %}


# Staking Dashboard

### Balances

There are a few new concepts around how your $ANYONE tokens are held and used in the protocol!

**Relay Locks**, **Relay Rewards**, **Staking** and **Staking Rewards** are all handled in a single smart contract on Ethereum - this contract makes it easier to seamlessly transition tokens between the different use cases.

#### Your tokens could be in these places:

* Within your wallet, as normal.&#x20;
* Within the protocol contract, but not allocated to a lock or staked: this is called your **Available** balance (**1** in screenshot below).
* Locked to register a (non hardware) relay or to delegate a lock for .someone else’s relay (**2** in screenshot below)
* Staked to a relay family (**3** in screenshot below).
* Vaulted - a ‘vault’ represents a **pending unlock**.

<div align="left"><figure><img src="/files/dBU7XrLfDVyby97AzL7t" alt=""><figcaption></figcaption></figure></div>

You can see the sum total of tokens in these vaults on the Home page (**4** in screenshot below). If any of the vaults are expired (which means their cooldown has ended), you will be able to redeem them on the Home page (**5** in screenshot below).

{% hint style="info" %}

Tokenomic change! Instead of a fixed lock period, both **relay locks** and **stakes** now have a cool down period - when you unlock or un-stake, your tokens are moved to a **vault** with a fixed unlock period. As with other protocols, when you initiate the unlock process your relay becomes ineligible for rewards and you stop earning stake yield.
{% endhint %}

### Rewards

Even though there are now two sources of rewards;

* Relay Rewards
* Staking Rewards

Both are redeemed from the **same place** on the Home page (**1** in screenshot below).

The total redeemable amount is the sum of staking rewards + relay rewards, shown in the previous column (**2** circled in screenshot below).

Instead of going directly to your wallet, by default, redeemed rewards go to your **available contract balance** to be easily reused in the protocol.&#x20;

<div align="left"><figure><img src="/files/yevZnEb78vDJ2EcaBTKg" alt=""><figcaption></figcaption></figure></div>

### Staking

Anyone Protocol introduces a new kind of staking - staking for economic security. Instead of blindly depositing tokens, you must **stake to a specific relay family** - where the relay family is designed by the operators wallet. **5% of your staking rewards go to the operator you stake on**, encouraging people to run reliable families and engage with fellow holders to get their support.

#### APY

Staking APY is a variable. Much like the relay rewards, there is a fixed outflow of tokens currently set to be identical to the relay rewards (5000 tokens per day), which are divided between all eligible stake holders based on tokens.

As a point of reference initially with:

* 5% of total supply staked which would be a 32.5% APR.
* 30% of total supply staked which would be a 5% yearly APR.

Staking rewards will be boosted as revenue comes into the protocol, to further compensate holders for the key role they play in securing the network. In the near term, this can take the form of airdrops and other bonuses for stake holders.

### Staking Eligibility

Go to the **Staking** tab from the menu at the top of dashboard.&#x20;

Once there, you’ll be greeted by a list of all the relay families which shows your stakes and the total amount of tokens staked per family.

Once you stake to a relay family, your tokens accrue rewards **only if 50%+ of the relay family’s registered relays are active in the hourly epoch**. This is represented by the <mark style="color:green;">green</mark> or <mark style="color:red;">red</mark> **running** column (**1** in the screenshot below).

You can choose to stake all your tokens to a single family, or split them between multiple families.&#x20;

To stake (or unstake) click the three dots in the **Actions** column (**2** in the screenshot below).

<div align="left"><figure><img src="/files/ApTBP97sRDFU2bd1hRib" alt=""><figcaption></figcaption></figure></div>

Upon pressing stake, you will see a pop-up like the one pictured on the screenshot below.

You can either stake tokens sitting in your contract **Available** balance, or stake directly from your **Wallet**. The toggle in "Amount to stake" (**3** in the screenshot below) lets you switch between these locations.

Once you’ve selected the amount, click on **stake** and confirm the interaction.

<div align="left"><figure><img src="/files/JFpDoKwuYDItfEAbYmXB" alt="" width="375"><figcaption></figcaption></figure></div>

### Staking Rewards and Compounding

As you begin to accrue staking rewards, you’ll see them in the **Unclaimed Staking Rewards** value. Crucially, these rewards are auto-compounded without needing to be redeemed. However, for the purpose of testing, please try and interact, redeem, move them and more!&#x20;

As mentioned above, you can’t claim staking rewards in isolation - you need to redeem them with relay rewards from the homepage.

Visit the [Dashboard](https://dashboard.anyone.io/) to begin.


# Anyone Domains

### Your personal .anyone domains.

Referencing your personal .anyone domain to your Relay Operator wallet makes it recognisable and easier to identify for other holders of [$ANYONE](https://etherscan.io/token/0xfeac2eae96899709a43e252b6b92971d32f9c0f9) looking for Operators to stake towards.

The .anyone domain is a Web3 domain in the form of a NFT held by a wallet on [Base](https://www.base.org/), this NFT is acquired from [Unstoppable Domains](https://unstoppabledomains.com/) (UD).&#x20;

When the ANYONE [Rewards and Staking dashboard](https://dashboard.anyone.io/) identifies a Relay Operator wallet is holding the NFT for a .anyone domain it will automatically be listed and searchable on the staking tab as seen the picture below. You can hold multiple domains on the same wallet.

<div align="left"><figure><img src="/files/QParEEU2Jfwm7trCe39Z" alt="" width="563"><figcaption></figcaption></figure></div>

### What are Web3 domains?

You can read more about Web3 domains from UD [here](https://support.unstoppabledomains.com/support/solutions/articles/48001181690-what-are-web3-domains-), as well as finding guides on how to manage Web3 domains on the UD control panel [here](https://support.unstoppabledomains.com/support/solutions/articles/48001188302-user-guide-for-web3-domains).

### Acquire .anyone domains

1. Go to [https://unstoppabledomains.com](https://unstoppabledomains.com/) and press **Login**. To login without using email or creating an account, press the wallet icon.

<div align="left"><figure><img src="/files/mN72MPWIUCoHzv2ZbiDw" alt="" width="375"><figcaption></figcaption></figure></div>

2. Sign the signature when prompted by your wallet. As mentioned, the signature should **not** trigger any approval, blockchain transaction or cost any gas fees.

<div align="left"><figure><img src="/files/mp4iArvxjJoVDzGClqge" alt="" width="375"><figcaption></figcaption></figure></div>

3. Search the .anyone domains of your liking and add to cart.

<div align="left"><figure><img src="/files/2TjoNEgUB4Qu1FRR8xEh" alt="" width="563"><figcaption></figcaption></figure></div>

4. Go to checkout and select preferred payment method, in this example we choose **Crypto**.

<div data-with-frame="true"><figure><img src="/files/XNMmiei5nnnCYRBeTYd6" alt=""><figcaption></figcaption></figure></div>

5. When prompted to **Pay now** you have the option to choose to pay using Base, Ethereum or Polygon.

<div align="left"><figure><img src="/files/cktS4tdaS6PuBWsUzXiN" alt="" width="375"><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/kRblVkm3nD65bUegMg1v" alt="" width="563"><figcaption></figcaption></figure></div>

6. After a while when the payment has been processed your domain will show up under **My Domains**.

<div data-with-frame="true"><figure><img src="/files/wI2QOuBVMTdRr6GLfL8C" alt="" width="563"><figcaption></figcaption></figure></div>

### The .anyone NFT

Unstoppable Domains take the form of an NFT on Base chain when acquired by users. For your domain to appear on the dashboard, your wallet must hold the NFT.&#x20;

{% hint style="danger" %}
**Display Criteria**

Note: for your .anyone domains to display correctly on the dashboard, you must use your wallet as the **minting wallet** on Unstoppable, which gives you custody over the NFT. \
\
Read below on how to ensure this is the case.
{% endhint %}

#### Minting a new NFT

Normally when acquiring domains the NFT will be minted to a non-custody wallet provided by Unstoppable Domains on Base. It is recommended to instead use your **relay operator** address so that your domain can be linked to the dashboard. To do so, click on the three dots next to the wallet address you would like to set and press "**Use as Minting Wallet**".&#x20;

<div align="left" data-with-frame="true"><figure><img src="/files/Clopczf4jKXGtcsSPJLe" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Please note that it may take up to 2-3 hours for the domain to become visible on the [Rewards Dashboard](/dashboard).
{% endhint %}

#### Transferring your NFT&#x20;

If you minted a domain previously, but did not gain custody of the NFT, you will need to manually transfer the domain back to your wallet.&#x20;

1. Go to the "[My Domains](https://unstoppabledomains.com/domains)" and click on the domain you'd like to move to your own wallet.\
   On the left-hand side, scroll down to "**Transfer**". You will want to copy and paste your wallet address that you want to use manage the domain. Please be sure to check all of the boxes. Then select "**Transfer Domain**" to confirm this change.&#x20;

<div align="left"><figure><img src="/files/ncHYAAyxI4zqPfQ275SJ" alt="" width="563"><figcaption></figcaption></figure></div>

The domain will now be transferred. Once complete, you will be able to access the full management options.

<figure><img src="/files/ftcskoJX6N84bn7cEwWy" alt=""><figcaption></figcaption></figure>

You can verify the NFT has been transferred by searching for your wallet on [Basescan](https://basescan.org/) and go to the "**NFT Transfers**" section.

### Map your long form .anyone address to your domain

1. Go to the "[My Domains](https://unstoppabledomains.com/domains)" and choose the domain you'd like to map your hidden service address to, then go to the "**Crypto**" section.
2. Click "**+ Add Currency**" and search for "**ANyONe Protocol**"
3. Input the long form hidden service address in the field named "**ANYONE**".

{% hint style="info" %}
Following this [guide](/sdk/native-sdk/tutorials/services1#apt) you can fetch your long form address located by `sudo cat /var/lib/anon/anon_service/hostname` &#x20;
{% endhint %}

<figure><img src="/files/UFHLqbDQPQ1ccnyWqHgL" alt=""><figcaption></figcaption></figure>

4. Choose "**Confirm Changes**" and apply the change by signing using your wallet. This signature is does **not** require gas and should **not** prompt any approval!
5. When changes has applied and the DNS has been mapped it will be visible at <https://dns-stage.ec.anyone.tech/tld/anyone>.

### Updating and resolving .anyone DNS addresses

To update and resolve yours and others personal .anyone DNS addresses you can fetch the file onto your relays [DataDirectory](/sdk/native-sdk/manual#datadirectory-dir) by typing:

{% code expandable="true" %}

```bash
sudo curl https://dns.ec.anyone.tech/tld/anyone | sudo tee /var/lib/anon
```

{% endcode %}


# Customize gas settings and spending cap

Gas fees for blockchain transactions is a fact that we can't escape, but it is possible to manage and reduce them.

For every transaction you send using a wallet, you'll need to pay gas. For a general description on how gas works go [here](https://support.metamask.io/more-web3/learn/user-guide-gas/).

You can easily customize the gas you pay for each transaction according to your circumstances. For example, sometimes you may want to pay more to help your transaction be processed sooner; other times, you may be happy to wait.

First, let's define the various terms you'll encounter when customizing gas settings:

* **The gas limit**

  The *gas limit* is the **maximum amount of gas units you are willing to pay for** in order to carry out a transaction or EVM operation.
* **The max priority fee**

  The *max priority fee* goes to the validator, and incentivizes them to prioritize your transaction.
* **The max fee**

  The max fee is the total, global amount paid for your transaction: **base fee + priority fee.**

When setting custom gas fees it's important to check the historical Gas Prices on [Ethereum Gas Tracker](https://etherscan.io/gastracker#historicaldata) as a reference. Mind that low values may end up in very slow transactions as well as never succeeding.&#x20;

**Selecting the slower options are generally sufficient enough for less urgent transactions.**

{% tabs %}
{% tab title="Metamask" %}
When you start to send a transaction, you'll see a pencil icon by the estimated fee details allowing you to edit your gas option:

<div align="left"><img src="https://csct-assets.infura-ipfs.io/ipfs/QmXWyPZuinNyqyy4eUzh7G5C8AM1Gu3iUoCWcLvE6kfD1y" alt="" width="375"></div>

Clicking on this button will allow you to choose between three options, 'Low', 'Market', or 'Aggressive'. These describe the amount of gas you're choosing to pay, and have these main implications:

* '**Low**' involves paying less for gas, and most likely waiting longer for your transaction to complete.
* '**Market**' sets your gas to reflect the current market rates.
* '**Aggressive**' enables you to be more forceful with your transaction, and have it completed as soon as possible by paying more.
* '**Advanced**' enables you customize gas parameters directly.

<div align="left"><img src="https://csct-assets.infura-ipfs.io/ipfs/Qmci4NQ4KzC1paLyJBJbEjfHvXQjHAmjqEdZ9meXTVrLDD" alt="" width="375"></div>

Select '**Advanced**' if you wish to set the a custom gas value. Mind that low values may end up in very slow transactions times as well as never succeeding. It is important to check [Ethereum Gas Tracker](https://etherscan.io/gastracker#historicaldata) as a reference when settings custom values.

<div align="left"><figure><img src="/files/qtw2HFXZ1hTLKoVFvwG9" alt="" width="375"><figcaption></figcaption></figure></div>

You can also save the values as default for future transactions.

{% endtab %}

{% tab title="Rabby" %}
When you start to send a transaction, you'll see a drop-down icon by the estimated fee details allowing you to edit your gas option:

<div align="left"><figure><img src="/files/7eej9zMX3AHFIeJl6IDy" alt="" width="255"><figcaption></figcaption></figure></div>

Clicking on this drop-down will allow you to choose between three options, 'Low', 'Market', or 'Aggressive'. These describe the amount of gas you're choosing to pay, and have these main implications:

* '**Slow**' involves paying less for gas, and most likely waiting longer for your transaction to complete.
* '**Normal**' sets your gas to reflect the current market rates.
* '**Fast**' enables you to be more forceful with your transaction, and have it completed as soon as possible by paying more.
* '**Custom**' enables you customize gas parameters directly.

<div align="left"><figure><img src="/files/Dwn1zIPbNgy2kPtSq27d" alt="" width="375"><figcaption></figcaption></figure></div>

Select '**Custom**' if you wish to set the a custom gas value. Mind that low values may end up in very slow transactions times as well as never succeeding. It is important to check [Ethereum Gas Tracker](https://etherscan.io/gastracker#historicaldata) as a reference when settings custom values.

<div align="left"><figure><img src="/files/Ta42imuyhxWYcLbVhqik" alt="" width="375"><figcaption></figcaption></figure></div>

{% endtab %}
{% endtabs %}

#### **References:**&#x20;

{% embed url="<https://support.metamask.io/configure/transactions/how-to-customize-gas-settings>" %}

{% embed url="<https://support.rabby.io/hc/en-us/articles/11495315064847-How-to-speed-up-or-cancel-a-pending-transaction>" %}

## How to customize token approvals with a spending cap

When you interact with any dapp that involves your ANYONE token holdings in some way or another, you're likely to have to approve its access to that token's smart contract. Token allowances are specific to one token. That means that if you've granted an allowance for the Relay and Staking dashboard to access your 100 ANYONE, for example then you only need to sign another signature when the approved spending cap is reached or the approval is revoked.&#x20;

In some cases, token allowances that exceed what you need for any single transaction can be convenient; it would be time-consuming to have to grant permission anew for every transaction you wish to make on the Relay and Staking Dashboard. Let's take a specific example, if you operate 5 non-relays that requires 100 ANYONE to lock per relay, instead for signing one approval for 100 ANYONE you can save time and transaction fees by approve a spending cap for 500 ANYONE. Here is how to do it:<br>

{% tabs %}
{% tab title="Metamask" %}

{% endtab %}

{% tab title="Rabby" %}
An interaction with a Relay and Rewards Dashboard that requires a token approval will call up a screen that reads "Spending cap request". you'll see a pencil icon allowing you to edit the spending cap:

<div align="left"><figure><img src="/files/ELsTKR2Sj8ryP5UkcJvN" alt="" width="375"><figcaption></figcaption></figure></div>

Edit&#x20;

<div align="left"><figure><img src="/files/rGmo3pw3Lbl8veUUvPbw" alt="" width="375"><figcaption></figcaption></figure></div>
{% endtab %}
{% endtabs %}


# Governance

🎉 Governance for Anyone Protocol is going live! The following pages contain information on registering for governance and the structure of proposals.&#x20;

{% hint style="info" %}
**Quick Links: Governance**\
Snapshot: snapshot.org/#/s:daoforanyone.eth\
Dashboard: <https://dashboard.anyone.io\\>
Discussion: <https://t.me/anyoneprotocol&#x20>;
{% endhint %}

Get started by registering for governance:

{% content-ref url="/pages/7mpwQmCKkChAY272G0Kx" %}
[Register for Governance](/governance/registering)
{% endcontent-ref %}


# Register for Governance

Governance is available to any user staking their $ANYONE tokens. Not staking yet? Find out how to stake and support our network's security at: <https://docs.anyone.io/dashboard/stake>.&#x20;

### Governance Mode

You can make your wallet eligible for governance voting by registering governance mode. This is a <mark style="color:$danger;">**one-way**</mark> operation: once you toggle governance mode on, you can't turn it back.&#x20;

Governance mode extends your un-stake duration from **7 days** to **30 days**. This applies to both current stakes and future stakes. But in return, every staked token represents 1 Voting Power in all governance proposals!

There is no other cost to governance; you will not use or spend tokens in registering for governance or in voting.&#x20;

#### Enabling Governance Mode

Togging governance mode on is a simple operation that can be performed from <https://dashboard.anyone.io>, by clicking <mark style="color:purple;">**Enable Governance.**</mark>&#x20;

<figure><img src="/files/caDdmw62hzr09JLiJonk" alt=""><figcaption></figcaption></figure>

This will initiate a single transaction that can be signed.&#x20;

#### Voting on Proposals

Voting can be done from the Snapshot space, whose ratification is the content of the first Anyone governance vote, from the link below:

{% embed url="<https://snapshot.org/#/s:daoforanyone.eth>" %}


# SDK & Integrations

Welcome to the Anyone SDK! The future of privacy is programmable - and we are all empowered to create the next generation of privacy apps for Anyone! The SDK docs will enable you to start the Anyone Client from code and route app traffic through it. \
\
The easiest way to get started is with the NPM SDK. Want to write your first line of code? Head over to the NPM [Tutorials](/sdk/npm/tutorials)! The client can also be started from a number of other frameworks, either through NPM in [Library methods](/sdk/npm/library), or natively through the binary [Native SDK](/sdk/native-sdk), and in a number of other frameworks to be released!

{% content-ref url="/pages/S7NzyHn6PWAJw42sH8fz" %}
[NPM SDK](/sdk/npm)
{% endcontent-ref %}

{% content-ref url="/pages/ZG7BDEJVsvAJjYpZzJfQ" %}
[Native SDK](/sdk/native-sdk)
{% endcontent-ref %}

{% content-ref url="/pages/RpRjafj4zH74eGVD8qXw" %}
[iOS SDK \[Beta\]](/sdk/ios-sdk-beta)
{% endcontent-ref %}


# NPM SDK

The Anyone NPM SDK is a client module installable via Node package manager, providing libraries to interact with the Anyone Network from code and the command line. Ready to make privacy programmable?

### See the Tutorial

Head straight over to our first tutorial - [Hello Anon World I](/sdk/npm/tutorials/i) - to understand how to set your environment up and build your first circuit through the Anyone Network from code.&#x20;

{% content-ref url="/pages/YRiIPn4kjqklBEnSuaFG" %}
[Hello Anon World I](/sdk/npm/tutorials/i)
{% endcontent-ref %}

### Explore for Yourself&#x20;

{% content-ref url="/pages/LN4HHdprAlJsRcALdzyK" %}
[Installation and CLI usage](/sdk/npm/install)
{% endcontent-ref %}

{% content-ref url="/pages/WAoxArmmKj4oCpmDhO03" %}
[Broken mention](broken://pages/WAoxArmmKj4oCpmDhO03)
{% endcontent-ref %}


# Installation and CLI usage

{% tabs %}
{% tab title="Ubuntu" %}
**Have** **npm and Node.js installed already? Skip to step 6. If not, read below**

1. Update your repo

```bash
sudo apt-get update --yes
```

2. Install npm

```bash
sudo apt-get install npm --yes
```

3. Install Node Version Manager

```bash
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.0/install.sh | bash
```

4. Update the terminal

```bash
source ~/.bashrc
```

5. Install Node.js version 20

```bash
nvm install 20
```

6. Use Node.js version 20

```bash
nvm use 20
```

7. Install the anyone-client

```bash
npm install @anyone-protocol/anyone-client
```

8. If you wish to use it personally, start the anyone-client.&#x20;

```bash
npx anyone-client
```

Resource: <https://www.npmjs.com/package/@anyone-protocol/anyone-client>
{% endtab %}

{% tab title="macOS" %}
**Have** **npm and Node.js installed already? Skip to step 4. If not, read below**\
\
NPM installation replicates the installation guide [here](https://nodejs.org/en/download/package-manager). You can follow this guide on the Terminal app on your Mac.&#x20;

1. Install nvm by&#x20;

```
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.0/install.sh | bash
```

2. Use nvm to install Node.js 20

```
nvm install 20
```

3. Verify that you have installed Node.js and npm by ensuring you get a version code for each of these commands

```
node -v
npm -v
```

4. Install the anyone-client

```bash
npm install @anyone-protocol/anyone-client
```

5. If you wish to use it personally, start the anyone-client.&#x20;

```bash
npx anyone-client
```

Resource: <https://www.npmjs.com/package/@anyone-protocol/anyone-client>
{% endtab %}

{% tab title="Windows" %}
**Have** **npm and Node.js installed already? Skip to step 4. If not, read below**\
\
NPM installation replicates the installation guide [here](https://nodejs.org/en/download/package-manager). You can follow this guide on the Command Prompt app on your Desktop.

1. Install fnm (fast node manager) by&#x20;

```
winget install Schniz.fnm
```

2. Use fnm to install Node.js 20

```
fnm env --use-on-cd | Out-String | Invoke-Expression
fnm use --install-if-missing 20
```

3. Verify that you have installed Node.js and npm by ensuring you get a version code for each of these commands

```
node -v
npm -v
```

4. Install the anyone-client

```bash
npm install @anyone-protocol/anyone-client
```

5. If you wish to use it personally, start the anyone-client.&#x20;

```bash
npx anyone-client
```

Resource: <https://www.npmjs.com/package/@anyone-protocol/anyone-client>
{% endtab %}
{% endtabs %}

## Run from CLI

The Anyone Protocol NPM package provides a command-line interface (CLI) that allows you to easily run and configure the Anyone client. This page details how to use the CLI and the available options.

### Running the Anyone Client

To run the Anyone client using the CLI, use the following command:

```sh
npx anyone-client
```

This command will start the client with default port settings.

### Default Port Settings

When run without any options, the Anyone Client uses the following default ports:

* SocksPort: 9050
* ControlPort: 9051
* OrPort: 9001

### CLI Options

You can customize the client's behavior using various command-line options:

| Option | Description                                 | Default  |
| ------ | ------------------------------------------- | -------- |
| `-s`   | Set the SocksPort                           | 9050     |
| `-c`   | Set the ControlPort (use 0 to disable)      | 9051     |
| `-o`   | Set the OrPort                              | 9001     |
| `-v`   | Enable verbose mode for full client logs    | Disabled |
| `-f`   | Set the path to a custom anonrc config file | None     |
| `-b`   | Set the path to a custom anon binary        | None     |

#### Example Usage

Here's an example of how to use these options:

```sh
npx anyone-client -s 9150 -c 0 -o 9101 -f ./customAnonrc -b /usr/local/bin/anon -v
```

This command will:

* Set the SocksPort to 9150
* Disable the ControlPort
* Set the OrPort to 9101
* Use a custom anonrc file located at './customAnonrc'
* Use a custom anon binary located at '/usr/local/bin/anon'
* Enable verbose mode

### Important Notes

1. When changing ports, ensure they don't conflict with other services on your system.
2. The `-b` option allows you to use a preinstalled anon binary instead of the one that comes with the package.

### Terms and Agreements

To bypass the user agreement automatically, you can create a file named 'terms-agreement' in the working directory. This file should contain the line 'agreed' to be considered valid.


# Library methods

Welcome to the API Reference for our Anyone Network Library. This documentation provides detailed information about the classes and methods available in our library, allowing you to integrate the functionality of the anon binary into your applications effectively.

### Overview

Currently our library consists of three main classes, each serving a specific purpose in interacting with the Anyone Network:

1. **Anon**: This class allows you to run and manage an anon process with various configuration options. It provides methods to start and stop the Anon process, check its status, and retrieve port information.
2. **AnonSocksClient**: This class enables you to send HTTP requests through the Anon network using a SOCKS proxy. It wraps around the Axios library, providing methods for common HTTP operations like GET, POST, PUT, DELETE, and PATCH.
3. **AnonControlClient**: This class facilitates interaction with the Anon Control Port, allowing you to authenticate, send commands, and manage circuits within the Anon network.

### How to Use This Documentation

Each class has its own dedicated page in this API Reference. On these pages, you'll find:

* Detailed descriptions of the class constructor and its parameters
* A list of all available methods, their parameters, and return types
* Explanations of key concepts and data structures used by the class
* Usage examples to help you get started

### Quick Links

* [Anon](/sdk/npm/library/anon)
* [AnonSocksClient](/sdk/npm/library/anonsocksclient)
* [AnonControlClient](/sdk/npm/library/anoncontrolclient)


# Anon

The `Anon` class allows you to run and manage an Anon client with various configuration options.

### Constructor

#### `constructor(options?: Partial<AnonConfig>)`

Creates a new instance of the Anon class.

* `options` (optional): `Partial<AnonConfig>` - An object containing partial configuration options for the Anon client.

### AnonConfig Properties

* `displayLog`: `boolean` - Whether to display logs. Default: `false`
* `useExecFile`: `boolean` - Whether to use `execFile` instead of `spawn`. Default: `false`
* `socksPort`: `number` - The SOCKS port to use. Default: `9050`
* `orPort`: `number` - The OR (Onion Routing) port to use. Default: `0`
* `controlPort`: `number` - The control port to use. Default: `9051`
* `binaryPath`: `string | undefined` - The path to the Anon binary. Default: `undefined`

### Methods

#### `getSOCKSPort(): number`

Retrieves the SOCKS port number configured for the Anon instance.

Returns: The SOCKS port number.

#### `getControlPort(): number`

Retrieves the Control port number configured for the Anon instance.

Returns: The Control port number.

#### `getORPort(): number`

Retrieves the OR (Onion Routing) port number configured for the Anon instance.

Returns: The OR port number.

#### `async start(): Promise<void>`

Starts the Anon client with the options configured in the constructor.

Throws: An error if the Anon process is already started.

#### `async stop(): Promise<void>`

Stops the Anon client.

#### `isRunning(): boolean`

Checks if the Anon client is currently running.

Returns: `true` if Anon is running, `false` otherwise.

### Usage Example

```javascript
javascriptCopyimport { Anon } from '@anyone-protocol/anyone-client';

const anonClient = new Anon({
  displayLog: true,
  socksPort: 9060
});

await anonClient.start();
console.log(`SOCKS Port: ${anonClient.getSOCKSPort()}`);
console.log(`Control Port: ${anonClient.getControlPort()}`);
console.log(`OR Port: ${anonClient.getORPort()}`);

// ... use the Anon client ...

if (anonClient.isRunning()) {
  await anonClient.stop();
}
```


# AnonSocksClient

The `AnonSocksClient` class provides a way to send HTTP requests through the Anon network using a SOCKS proxy.

### Constructor

#### `constructor(anon: Anon, host?: string)`&#x20;

`constructor(socksPort: number, host?: string)`&#x20;

Creates a new instance of the AnonSocksClient class.

* `anon`: `Anon` - An instance of the Anon class, or
* `socksPort`: `number` - The SOCKS port to use
* `host`: `string` (optional) - The host to use for the SOCKS proxy. Default: `'127.0.0.1'`

### Methods

#### `get<T = any>(url: string, config?: AxiosRequestConfig): Promise<AxiosResponse<T>>`&#x20;

Sends a GET request to the specified URL through the Anon network.

* `url`: `string` - The URL to send the GET request to
* `config`: `AxiosRequestConfig` (optional) - Additional Axios request configuration Returns: A promise that resolves with the response data

#### `post<T = any>(url: string, data?: any, config?: AxiosRequestConfig): Promise<AxiosResponse<T>>`&#x20;

Sends a POST request to the specified URL through the Anon network.

* `url`: `string` - The URL to send the POST request to
* `data`: `any` (optional) - The data to be sent as the request body
* `config`: `AxiosRequestConfig` (optional) - Additional Axios request configuration Returns: A promise that resolves with the response data

#### `put<T = any>(url: string, data?: any, config?: AxiosRequestConfig): Promise<AxiosResponse<T>>`&#x20;

Sends a PUT request to the specified URL through the Anon network.

* `url`: `string` - The URL to send the PUT request to
* `data`: `any` (optional) - The data to be sent as the request body
* `config`: `AxiosRequestConfig` (optional) - Additional Axios request configuration Returns: A promise that resolves with the response data

#### `delete<T = any>(url: string, config?: AxiosRequestConfig): Promise<AxiosResponse<T>>`&#x20;

Sends a DELETE request to the specified URL through the Anyone Network.

* `url`: `string` - The URL to send the DELETE request to
* `config`: `AxiosRequestConfig` (optional) - Additional Axios request configuration Returns: A promise that resolves with the response data

#### `patch<T = any>(url: string, data?: any, config?: AxiosRequestConfig): Promise<AxiosResponse<T>>`&#x20;

Sends a PATCH request to the specified URL through the Anyone Network.

* `url`: `string` - The URL to send the PATCH request to
* `data`: `any` (optional) - The data to be sent as the request body
* `config`: `AxiosRequestConfig` (optional) - Additional Axios request configuration Returns: A promise that resolves with the response data

Usage Example

```javascript
import { Anon, AnonSocksClient } from '@anyone-protocol/anyone-client';

const anon = new Anon();
await anon.start();

const client = new AnonSocksClient(anon);

try {
  const response = await client.get('https://api.example.com/data');
  console.log(response.data);

  const postResponse = await client.post('https://api.example.com/users', { name: 'John Doe' });
  console.log(postResponse.data);
} catch (error) {
  console.error('Error:', error.message);
} finally {
  await anon.stop();
}
```


# AnonControlClient

The `AnonControlClient` class provides a way to interact with the Anon Control Port, allowing you to authenticate, send commands, and manage circuits.

### Constructor

`constructor(host: string = '127.0.0.1', port: number = 9051)` Creates a new instance of the AnonControlClient class.

* `host`: `string` - The host of the Anon Control Port. Default: `'127.0.0.1'`
* `port`: `number` - The port number of the Anon Control Port. Default: `9051`

### Methods

#### `authenticate(password: string = 'password'): Promise<void>`

Authenticates the client with the Anon Control Port.

* `password`: `string` - The password for authentication. Default: `'password'` Returns: A promise that resolves when authentication is successful.

#### `sendCommand(command: string): Promise<string>`

Sends a command to the Anon Control Port.

* `command`: `string` - The command to send Returns: A promise that resolves with the response from the Anon Control Port.

#### `circuitStatus(): Promise<CircuitStatus[]>`

Retrieves the current circuit status. Returns: A promise that resolves with an array of CircuitStatus objects.

#### `extendCircuit(options: ExtendCircuitOptions = {}): Promise<number>`

Extends an existing circuit or creates a new one.

* `options`: `ExtendCircuitOptions` - Options for extending the circuit Returns: A promise that resolves with the circuit ID.

#### `closeCircuit(circuitId: number): Promise<void>`

Closes a specified circuit.

* `circuitId`: `number` - The ID of the circuit to close Returns: A promise that resolves when the circuit is closed.

#### `getRelayInfo(fingerprint: string): Promise<RelayInfo>`

Retrieves information about a relay.

* `fingerprint`: `string` - The fingerprint of the relay Returns: A promise that resolves with a RelayInfo object.

#### `end(): void`

Closes the connection to the Anon Control Port.

### Interfaces

`CircuitStatus`

* `circuitId`: `number`
* `state`: `string`
* `relays`: `Relay[]`
* `buildFlags`: `string[]`
* `purpose`: `string`
* `timeCreated`: `Date`

`Relay`

* `fingerprint`: `string`
* `nickname`: `string`

`ExtendCircuitOptions`

* `circuitId?`: `number`
* `serverSpecs?`: `string[]`
* `purpose?`: `'general' | 'controller'`

`RelayInfo`

* `fingerprint`: `string`
* `nickname`: `string`
* `ip`: `string`
* `orPort`: `number`
* `flags`: `string[]`
* `bandwidth`: `number`

Usage Example

```javascript
import { AnonControlClient } from '@anyone-protocol/anyone-client';

const client = new AnonControlClient();

async function example() {
  try {
    await client.authenticate('your_password');
    
    const circuits = await client.circuitStatus();
    console.log('Current circuits:', circuits);

    const newCircuitId = await client.extendCircuit();
    console.log('New circuit created with ID:', newCircuitId);

    const relayInfo = await client.getRelayInfo('RELAY_FINGERPRINT');
    console.log('Relay info:', relayInfo);

    await client.closeCircuit(newCircuitId);
    console.log('Circuit closed');
  } catch (error) {
    console.error('Error:', error.message);
  } finally {
    client.end();
  }
}

example();
```


# Tutorials


# Hello Anon World I

Welcome to our **npm** tutorial series, walking you through using **Anyone** with **Javascript**. We'll walk you through starting the Anyone client, routing your first request through and some cool features built into the SDK! Let's get started.

{% hint style="info" %}
**Installing NPM Package**

This tutorial assumes you have already installed npm and the anyone-client package (either globally or in your local development folder). If you haven't, check out [Installation and CLI usage](/sdk/npm/install)
{% endhint %}

## Setting Up Your Environment

For this tutorial, we will be using[ Visual Studio Code](https://code.visualstudio.com/) to view and edit code, but you can choose any IDE. Create a new directory for this tutorial, in our case `sdk-test.`

We will be running our code as a node module, which can be instantiated using npm. In addition to your IDE, you will need a terminal window open in the same directory (this can also be done from within VS Code).&#x20;

From your terminal, run&#x20;

```
npm init es6 --save  
```

This will setup your project directory as an npm module, creating a `package.json` file and configuring it as a module. Next, from your IDE, create a local file to run your code. In our case, this is `hello.js.`

<div data-full-width="true"><figure><img src="/files/9Yo8Ev85eGmsJVHDCnto" alt="" width="318"><figcaption><p>Creating file hello.js within the project directory</p></figcaption></figure></div>

## Importing and Starting Anon

We will be importing **anon**, the underlying software binary for Anyone, into our newly created `hello.js` file:

```javascript
import { Anon } from "@anyone-protocol/anyone-client";
```

The simplest way to start the anon binary is to create a new *instance* of the imported library, and calling its first function `.start()`&#x20;

<pre class="language-javascript"><code class="lang-javascript"><strong>import { Anon } from "@anyone-protocol/anyone-client";
</strong>
const anon = new Anon();
anon.start();
</code></pre>

To run your program, return to your terminal, and run `node` followed by your program name:

{% code title="Your Terminal" fullWidth="false" %}

```
node hello.js
```

{% endcode %}

This starts the client, which will automatically negotiate a circuit within the Anyone Network! You can see this happen in real time. Once the client has started, it won't shut off automatically - it will continue to run until stopped.&#x20;

<figure><img src="/files/TbFFJ3sDxoriCvyrONTx" alt="" width="563"><figcaption></figcaption></figure>

To terminate, type `Ctrl-C` or `Cmd-C` into the terminal window depending on your OS. You've now created your first circuit from code!

<details>

<summary>I get an error!</summary>

Make sure that you have npm and anyone-client installed. Check out [Installation and CLI usage](/sdk/npm/install)

</details>

## Starting and Stopping&#x20;

Let's make our code a little more robust, and give ourselves the ability to stop the client.&#x20;

The anon binary should be called from **asynchronous** functions to ensure the client can continue to run without blocking the rest of your application, and called within a **try-catch** block so that network issues can be handled gracefully. We will structure a simple asynchronous function **main** and run the same code.&#x20;

```javascript
import { Anon } from "@anyone-protocol/anyone-client";

async function main() {
    const anon = new Anon();
    try {
        await anon.start();    
    } catch(error) {
        console.log(error)
    }
}

main()
```

We now introduce our second client function `.stop()` - for now, let's stop the client 15 seconds after the circuit is created.

Lets put an **await** statement before the start function so the program waits for it to complete before stopping (though currently, this resolves immediately), add a 15 second wait, and put the stop function within the **finally** clause of the try-catch block (so that it runs regardless of any issues). In the future, we can replace this 15 second wait with some real commands!&#x20;

```javascript
    try {
        await anon.start();
        await new Promise(resolve => setTimeout(resolve, 15000));
    } catch(error) {
        console.log(error)
    } finally {
        await anon.stop()
    }
```

Check out the full source on [GitHub](https://github.com/anyone-protocol).&#x20;

And that's a wrap! You have now successfully started and stopped **anon** from JavaScript code! If you're ready to explore the range of functions available yourself, head straight to the API reference at [Library methods](/sdk/npm/library). If not, let's start making some requests over the internet!

{% content-ref url="/pages/CZUkttsockHsVXf1hmLG" %}
[Hello Anon World II](/sdk/npm/tutorials/ii)
{% endcontent-ref %}


# Hello Anon World II

In part II, we will introduce the AnonSocksClient and make our first request over the internet - fetching your (new) IP address! We will continue from the node module and codebase from [Hello Anon World I](/sdk/npm/tutorials/i).

### Anon Socks Client

The AnonSocksClient is used to tunnel http(s) requests through the network. It provides implementations for `get, post, delete`  and more that automatically use a running instance of the Anyone client. It can be imported much like the Anon library:

<pre class="language-javascript"><code class="lang-javascript"><strong>import { AnonSocksClient } from "@anyone-protocol/anyone-client";
</strong></code></pre>

and instantiated immediately after the instantiation of the main **anon** client, taking it as reference:

```javascript
// ..imports and function statements..
const anon = new Anon({ displayLog: false, socksPort: 9050, controlPort: 9051 });
const anonSocksClient = new AnonSocksClient(anon);
```

For those coming in from part I, you'll notice some new arguments in the **anon** instantiation - these are optional arguments that become relevant when dealing with SOCKS routing, circuit control and debugging. Seen in this code snippet are the default values for each one.

<details>

<summary>What <em>are</em> SOCKS? <span data-gb-custom-inline data-tag="emoji" data-code="1f9e6">🧦</span></summary>

These SOCKS aren't for your feet! SOCKS is an acronym for Socket Secure - an internet protocol that allows you to route your traffic to a 'proxy server' (i.e., a server that sits in between you and your eventual, varied list of destinations).&#x20;

Importantly, a SOCKS proxy server can run locally, listening to any requests made on a specific port (known as 'binding' to that port). In this case, the anon SOCKS process listens to any request made to the specified socksPort, forwards this through a circuit in the Anon network, and returns the result to whichever process makes the request.&#x20;

</details>

### Fetching our IP

Here, we will be calling `anonSocksClient.get` to fetch our IP through the network. We'll be using the public, free service at [https://api.ipify.org](<https://api.ipify.org >), but you can choose any that works as an API! We will simply call 'get' on the API, await its result and print the result:

```javascript
const response = await anonSocksClient.get('https://api.ipify.org?format=json');
console.log('Response:', response.data);
```

Let's see the AnonSocksClient setup and this logic in the full function (note that, for now, a short wait time is required after `anon.start()` and before making requests through the network).&#x20;

```javascript
import { Anon } from "@anyone-protocol/anyone-client";
import { AnonSocksClient } from "@anyone-protocol/anyone-client";

async function main() {
    const anon = new Anon();
    const anonSocksClient = new AnonSocksClient(anon);

    try {
        await anon.start();
        await new Promise(resolve => setTimeout(resolve, 15000));
        
        const response = await anonSocksClient.get('https://api.ipify.org?format=json');
        console.log('Response:', response.data);
        
    } catch(error) {
        console.log(error)
    } finally {
        await anon.stop()
    }
}

main()
```

Running `node <programName>.js` from the command line will show the same setup logs as before and then the result of the IP lookup! We're now, as far as external sites are concerned, coming out of Bayern, Germany. Cool!&#x20;

<figure><img src="/files/xUaagFEkB2CTSWJSjnsd" alt=""><figcaption></figcaption></figure>

See the full code on [GitHub](https://github.com/anyone-protocol).&#x20;

Now, lets look into more fine-tuned circuit control.


# Circuit Control I

So far, we've seen two libraries as part of the Anyone NPM SDK:&#x20;

* **Anon** - the Anyone Client, which negotiates and maintains circuits through the network and runs a proxy server to forward traffic
* **AnonSocksClient** - used in place of a typical requests library to forward get, post and other methods to the Anyone client!

Now, we will introduce one of the most powerful libraries - **AnonControlClient** - which interacts with the **control port** of the Anyone client and provides a new level of configurability. You can see circuit information that is hidden from most applications, send commands and manage circuits. Let's dive in!

### Starting and Authenticating

For obvious reasons, not every app running locally alongside the Anyone Client can see or modify its behavior. Processes need to *authenticate* themselves on the client's **control port** and the AnonControlClient is no exception. Let's import it, much like the other libraries.&#x20;

```javascript
import { AnonControlClient } from "@anyone-protocol/anyone-client"; 
```

The control client is then instantiated much like anon, specifying the host and port number of the client to bind to. `127.0.0.1` and `9051` are the default values and will work with the default Anon object.

```javascript
const anonControlClient = new AnonControlClient(); 

// You can also specify your host and port:
// const anonControlClient = new AnonControlClient(host: '127.0.0.1', port: 9051);
```

From there, assuming you have anon running anywhere in the local network, authenticating to the control port is simple

```javascript
await anonControlClient.authenticate();
```

Let's create a new file `control.js` and put this all together. Notice that, unlike the SOCKS client, the AnonControlClient is only instantiated after we have given the Anyone client time to establish itself. In addition, best practices are also to call `.end()` on the control client once it is complete.&#x20;

{% code title="control.js" %}

```javascript
import { Anon } from "@anyone-protocol/anyone-client";
import { AnonControlClient } from "@anyone-protocol/anyone-client";


async function main() {
   const anon = new Anon();
   
    try {
        await anon.start();
        await new Promise(resolve => setTimeout(resolve, 12000));

        const anonControlClient = new AnonControlClient(); 
        await anonControlClient.authenticate() 
        
        anonControlClient.end()
        
    } catch(error) {
        console.log(error)
    } finally {
        
        await anon.stop()
    }
}

main()
```

{% endcode %}

Running `node control.js` should yield the following success message:

<figure><img src="/files/8xeLBoXeSCZu44QXJts4" alt=""><figcaption></figcaption></figure>

### Reading Circuit Info

Now that we have authenticated, lets see what circuits have been created. The Anyone client often maintains multiple circuits within the network, and these can be seen as a JSON file with the `circuitsStatus()` function.&#x20;

```javascript
const circuits = await anonControlClient.circuitStatus();
console.log(JSON.stringify(circuits, null, 2));
```

Adding the above two lines after `.authenticate` and running as before will see a new JSON file outputted, like below:

<pre class="language-json" data-overflow="wrap"><code class="lang-json"><strong>[{
</strong>    "circuitId": 1,
    "state": "BUILT",
    "relays": [
      {
        "fingerprint": "54849A361F8CED0D1B70B722CB8B33E9071E5561",
        "nickname": "ATORDAuselive"
      }
    ],
    "buildFlags": [
      "ONEHOP_TUNNEL",
      "IS_INTERNAL",
      "NEED_CAPACITY"
    ],
    "purpose": "GENERAL",
    "timeCreated": "2024-11-08T12:10:46.596Z"
  },
...
</code></pre>

This shows a list of objects, each representing a single circuit - that shows the circuit's status and the first relay within it!&#x20;

To get further relay info, you could call `getRelayInfo`&#x20;

```javascript
const relayInfo0 = await anonControlClient.getRelayInfo(circuits[0].relays[0].fingerprint);
console.log('Relay [0] info:', relayInfo0);
```


# Circuit Control II

Now that we've used the **AnonControlClient** to see some circuit info, lets use it to assemble circuits with a little more customization!

<details>

<summary>Aside: Relay Fingerprints and Circuits</summary>

**Fingerprints**\
All relays have a unique identifier known as a fingerprint. Within the clients, authorities and even on-chain, the fingerprint is a relay's foremost identifier (even ahead of it's IP address). When selecting relays to build a circuit through, the fingerprint is how you specify them.

{% code title="Example Fingerprint" %}

```
41B78C1198702625B30FB225AE37AAC0B2FA4ED

```

{% endcode %}

**Circuits**\
A chain of relays that continually decrypt packets between an Anyone client and its destination (website or hidden service) is called a circuit.&#x20;

The default onion routing circuit in the Anyone Network is 3 hops- an Entry relay, Middle relay and Exit relay. This model provides a certain level of defence against malicious relays, as a single relay does not have enough information to deanonymize a user.&#x20;

However, circuits of any length can be constructed, including just one relay. However, if used to visit public websites, one of the relays must be an Exit.&#x20;

</details>

### Creating a Random Circuit&#x20;

We will be introducing the function `extendCircuits` , which is used to negotiate a new circuit. If no arguments are passed, `extendCircuits` will select a circuit using the default, randomized selection process, and return a circuit ID number.&#x20;

```javascript
const circuitID = await anonControlClient.extendCircuit();
console.log("Randomly created circuit:", circuitID);
```

This circuit ID can then be used to manage it further, including closing that specific circuit:

```javascript
await anonControlClient.closeCircuit(circuitID)
```

### Creating a Manual Circuit

The `extendCircuit` function can also take in an object structured like below, specifying the relays in order by fingerprint:

```javascript
{
    serverSpecs: [
        "41E262A8DAFB34B7AD5F82280813584101E2A47A",
        "41ADDE21CDCE614FF35DA58CDC15BC7A4A6DFE4D"
    ]
}
```

As is evident, it is not essential to specify a path of exactly three relays. So long as the first fingerprint has the `Guard` flag (which means the relay can act as an entry relay) and the final fingerprint has the `Exit` flag (which means it's able to forward your traffic over the clear-web), the circuit can be of any length. It can even consist of a single node, so long as that relay can be both an Entry and Exit node! &#x20;

How do we find the available fingerprints and the information needed to build a circuit from them? We have recently rolled out a new function in the NPM SDK: `routerStatus` that does exactly that!

#### Using the routerStatus Function

Note: Ensure that you have updated your npm client by running `npm update` within the working directory after it has been setup, to have access to this new function. Once the control client is setup, the new function simply needs to be called asynchronously:

```javascript
const routerStatus = await anonControlClient.routerStatus();
console.log(JSON.stringify(routerStatus, null, 2));
```

Once the promise is resolved, the function returns a JSON file listing. Let's have a look at its format:

```json
{
    "nickname": "AnyoneRelay02",
    "fingerprint": "Dz8wKhDvPf0z8Y1PCoWm9q3eMSE",
    "digest": "xBuwTXYjA2HoNP5jum/aJ4QPqCg",
    "publishedTime": "2038-01-01T00:00:00.000Z",
    "ip": "162.55.183.223",
    "orPort": 9001,
    "dirPort": 0,
    "flags": [
      "Fast",
      "Guard",
      "HSDir",
      "Running",
      "Stable",
      "V2Dir",
      "Valid"
    ],
    "bandwidth": 38000
},
{
  "nickname": "DeadZone",
```

Relays are listed in order, and have their own object which includes information on its IP, bandwidth and flags!

{% hint style="warning" %}
The introduction of custom circuits and the ability to build them based on manual criteria opens up a huge range of potential applications, including the use of algorithms and AI to create circuits. However, it also shifts the risk of de-anonymization onto you - the application developer - and subsequently your users. \
\
Be wary of the centralization risks of choosing circuits from a limited set of circuits, and look out for algorithms developed by the community to get the best of both worlds!
{% endhint %}

&#x20;


# Native SDK

The Anyone Client can be run directly by configuring and starting the binary. Thanks to the SOCKS framework, wherein the Anyone Client runs as a proxy server between your app and the internet, traffic from any framework can be forwarded through the network without requiring app-specific code.

To start, you can install the binary from the [Releases](/sdk/native-sdk/releases) - from there, see our examples for forwarding through a SOCKS Proxy, or for server-based applications, run an [Anyone Services I](/sdk/native-sdk/tutorials/services1).&#x20;

{% content-ref url="/pages/X3xdKqTa7YlEjG5Nhy1D" %}
[Releases](/sdk/native-sdk/releases)
{% endcontent-ref %}


# Releases

## Anyone Releases

{% hint style="info" %}
<https://github.com/anyone-protocol/ator-protocol/releases>
{% endhint %}

### Debian/Ubuntu Package

#### Install

1. Download package. \
   \
   Package name depends on your distributive version and CPU architecture. You can find full link to desired package file (`.deb`) in the release assets section on the [Github Releases](https://github.com/anyone-protocol/ator-protocol/releases) page.

```
wget https://github.com/anyone-protocol/ator-protocol/releases/download/<version>/<package_name>
```

2. Update repository information

```
apt-get -y update
```

3. Install package using apt

```
apt-get -y install ./anon_*.deb
```

{% hint style="success" %}
Alternatively, use the [apt repository](/relay/start/install-anon-on-linux/apt) to install the client on Debian.
{% endhint %}

#### Start

After installation you can start Anon by executing `anon` command in terminal. To modify configuration edit the `/etc/anon/anonrc` file.

#### Uninstall

```
apt-get -y remove anon
```

#### Uninstall and remove configuration files

```
apt-get -y purge anon
```

{% hint style="info" %}
Example script: [Connecting to Linux](broken://pages/4ITjXhVTJ07f0tLhv7jW) & [Install Anon on Linux (Relay Setup)](/relay/start/install-anon-on-linux)
{% endhint %}

### MacOS

#### Install

MacOS version of Anon is portable, you can install it by downloading `.zip` archive from the release assets section on the [Github Releases](https://github.com/anyone-protocol/ator-protocol/releases) page and extracting files from it. Make sure you download right archive for your system:

* for Intel: `amd64`
* for Apple Silicon: `arm64`

#### Start

1. Create `anonrc` file in the directory with extracted files.
2. Open terminal in directory with extracted files.
3. Start Anon by typing `./anon -f anonrc` in terminal.

#### Uninstall

To uninstall simply remove downloaded files.

{% hint style="info" %}
Example script: [Connecting to MacOS](broken://pages/znLs0yJOoMOCuOS0CamO)
{% endhint %}

### Windows

Windows version of Anon is portable, you can install it by downloading `.zip` archive from the release assets section on the [Github Releases](https://github.com/anyone-protocol/ator-protocol/releases) page and extracting files from it.

#### Start

1. Create `anonrc` file in the folder with extracted files.
2. Open PowerShell in directory with extracted files.
3. Start Anon by typing `./anon -f anonrc` in PowerShell.

#### Uninstall

To uninstall simply remove downloaded files.

{% hint style="info" %}
Example script: [Connecting to Windows](broken://pages/ZvFJsiFJkhA3197wsxh2)
{% endhint %}


# Manual

### SYNOPSIS

`anon [OPTION value]...`

***

### DESCRIPTION

Anon is a connection-oriented anonymizing communication service. Users choose a source-routed path through a set of nodes, and negotiate a "virtual circuit" through the network. Each node in a virtual circuit knows its predecessor and successor nodes, but no other nodes. Traffic flowing down the circuit is unwrapped by a symmetric key at each node, which reveals the downstream node.

Basically, Anon provides a distributed network of servers or relays ("onion routers"). Users bounce their TCP streams, including web traffic, ftp, ssh, etc., around the network, so that recipients, observers, and even the relays themselves have difficulty tracking the source of the stream.

By default, anon acts as a client only. To help the network by providing bandwidth as a relay, change the [`ORPort`](#orport-address-port-or-auto-flags) configuration option as mentioned below. Please also consult the documentation on the Anon Project’s website.

***

### COMMONLY USED OPTIONS

#### [`MyFamily`](#myfamily-fingerprint-fingerprint-1) `fingerprint,fingerprint,...`

#### [`BandwidthBurst` ](#bandwidthburst-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1)`N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

#### [`BandwidthRate`](#bandwidthrate-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1) `N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

#### [`AccountingMax` ](#accountingmax-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1)`N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

#### [`AccountingRule`](#accountingrule-sum-or-max-or-in-or-out-1) `sum|max|in|out`

#### [`AccountingStart`](#accountingstart-day-or-week-or-month-day-hh-mm-1) `day|week|month [day] HH:MM`

#### [`MaxMemInQueues`](#maxmeminqueues-n-bytes-or-kbytes-or-mbytes-or-gbytes-1) `N bytes|KBytes|MBytes|GBytes`

#### [`AddressDisableIPv6`](#addressdisableipv6-0-or-1-1) `0|1`

***

### COMMAND-LINE OPTIONS

Anon has a powerful command-line interface. This section lists optional arguments you can specify at the command line using the anon command.

Configuration options can be specified on the command line in the format `--OptionName OptionValue`, or in a configuration file. For instance, you can tell Anon to start listening for SOCKS connections on port 9999 by passing either `--SocksPort 9999` or `SocksPort 9999` on the command line, or by specifying `SocksPort 9999` in the configuration file.&#x20;

On the command line, quote option values that contain spaces. For instance, if you want Anon to log all debugging messages to debug.log, you must specify `--Log "debug file debug.log"`.

{% hint style="info" %}

#### Configuration options on the command line override those in configuration files. See '[THE CONFIGURATION FILE FORMAT](#the-configuration-file-format)' for more information.

{% endhint %}

The following options in this section are only recognized on the anon command line, not in a configuration file.

#### `-h, --help`

Display a short help message and exit.

#### `-f, --anonrc-file FILE`

Specify a new configuration file to contain further Anon configuration options, or pass - to make Anon read its configuration from standard input. (Default: `/etc/anon/anonrc`, or `$HOME/.anonrc` if the other path is not found.)

#### `--allow-missing-anonrc`

Allow the configuration file specified by `-f` to be missing, if the defaults-anonrc file (see below) is accessible.

#### `--defaults-anonrc FILE`

Specify a file in which to find default values for Anon options. The contents of this file are overridden by those in the regular configuration file, and by those on the command line. (Default: `/etc/anon/anonrc-defaults`.)

#### `--ignore-missing-anonrc`

Specify that Anon should treat a missing anonrc file as though it were empty. Ordinarily, Anon does this for missing default anonrc files, but not for those specified on the command line.

#### `--hash-password PASSWORD`

Generate a hashed password for control port access.

#### `--list-fingerprint [key type]`

Generate your keys and output your nickname and fingerprint. Optionally, you can specify the key type as rsa (default) or ed25519.

#### `--verify-config`

Verify whether the configuration file is valid.

#### `--dump-config short|full`

Write a list of Anon’s configured options to standard output. When the short flag is selected, only write the options that are different from their default values. When full is selected, write every option.

#### `--service install [--options command-line options]`

Install an instance of Anon as a Windows service, with the provided command-line options.

#### `--service remove|start|stop`

Remove, start, or stop a configured Anon Windows service.

#### `--nt-service`

Used internally to implement a Windows service.

#### `--list-anonrc-options`

List all valid options.

#### `--list-deprecated-options`

List all valid options that are scheduled to become obsolete in a future version. (This is a warning, not a promise.)

#### `--list-modules`

List whether each optional module has been compiled into Anon. (Any module not listed is not optional in this version of Anon.)

#### `--version`

Display Anon version and exit. The output is a single line of the format "Anon version \[version number]." (The version number format is as specified in version-spec.txt.)

#### `--quiet|--hush`

Override the default console logging behavior. By default, Anon starts out logging messages at level "notice" and higher to the console. It stops doing so after it parses its configuration, if the configuration tells it to log anywhere else. These options override the default console logging behavior. Use the `--hush` option if you want Anon to log only warnings and errors to the console, or use the `--quiet` option if you want Anon not to log to the console at all.

#### `--keygen [--newpass]`

Running anon `--keygen` creates a new **ed25519** master identity key for a relay, or only a fresh temporary signing key and certificate, if you already have a master key. Optionally, you can encrypt the master identity key with a passphrase. When Anon asks you for a passphrase and you don’t want to encrypt the master key, just don’t enter any passphrase when asked.

Use the `--newpass` option with `--keygen` only when you need to add, change, or remove a passphrase on an existing **ed25519** master identity key. You will be prompted for the old passphrase (if any), and the new passphrase (if any).

Note When generating a master key, you may want to use `--DataDirectory` to control where the keys and certificates will be stored, and `--SigningKeyLifetime` to control their lifetimes. See [SERVER OPTIONS](#server-options) to learn more about the behavior of these options. You must have write access to the specified [`DataDirectory`](#datadirectory-dir). To use the generated files, you must copy them to the DataDirectory/keys directory of your Anon daemon, and make sure that they are owned by the user actually running the Anon daemon on your system.

#### `--passphrase-fd FILEDES`

File descriptor to read the passphrase from. Note that unlike with the anon-gencert program, the entire file contents are read and used as the passphrase, including any trailing newlines. If the file descriptor is not specified, the passphrase is read from the terminal by default.

#### `--key-expiration [purpose] [--format iso8601|timestamp]`

The purpose specifies which type of key certificate to determine the expiration of. The only currently recognised purpose is "sign".

Running `anon --key-expiration` sign will attempt to find your signing key certificate and will output, both in the logs as well as to stdout. The optional `--format` argument lets you specify the time format. Currently, **ISO8601** and timestamp are supported. If `--format` is not specified, the signing key certificate’s expiration time will be in ISO-8601 format. For example, the output sent to stdout will be of the form: "**signing-cert-expiry: 2017-07-25 08:30:15 UTC**". If `--format` timestamp is specified, the signing key certificate’s expiration time will be in Unix timestamp format. For example, the output sent to stdout will be of the form: "`signing-cert-expiry: 1500971415`".

**`--dbg-...`**

Anon may support other options beginning with the string "`dbg`". These are intended for use by developers to debug and test Anon. They are not supported or guaranteed to be stable, and you should probably not use them.

***

### THE CONFIGURATION FILE FORMAT

All configuration options in a configuration are written on a single line by default. They take the form of an option name and a value, or an option name and a quoted value (option value or option "value"). Anything after a `#` character is treated as a comment. Options are case-insensitive. C-style escaped characters are allowed inside quoted values. To split one configuration entry into multiple lines, use a single backslash character (`\`) before the end of the line. Comments can be used in such multiline entries, but they must start at the beginning of a line.

Configuration options can be imported from files or folders using the `%include` option with the value being a path. This path can have wildcards. Wildcards are expanded first, then sorted using lexical order. Then, for each matching file or folder, the following rules are followed: if the path is a file, the options from the file will be parsed as if they were written where the `%include` option is. If the path is a folder, all files on that folder will be parsed following lexical order. Files starting with a dot (`.`) are ignored. Files in subfolders are ignored. The `%include` option can be used recursively. New configuration files or directories cannot be added to already running Anon instance if [`Sandbox`](#sandbox-0-or-1) is enabled.

The supported wildcards are `*` meaning any number of characters including none and `?` meaning exactly one character. These characters can be escaped by preceding them with a backslash (`\`), except on Windows. Files starting with a dot (`.`) are not matched when expanding wildcards unless the starting dot is explicitly in the pattern, except on Windows.

By default, an option on the command line overrides an option found in the configuration file, and an option in a configuration file overrides one in the defaults file.

This rule is simple for options that take a single value, but it can become complicated for options that are allowed to occur more than once: if you specify **four** SocksPorts in your configuration file, and **one** more [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) on the command line, the option on the command line will replace **all** of the SocksPorts in the configuration file. If this isn’t what you want, prefix the option name with a plus sign (`+`), and it will be appended to the previous set of options instead. For example, setting `SocksPort 9100` will use only port `9100`, but setting `+SocksPort 9100` will use ports `9100` and `9050` (because this is the default).

Alternatively, you might want to remove every instance of an option in the configuration file, and not replace it at all: you might want to say on the command line that you want no SocksPorts at all. To do that, prefix the option name with a forward slash (`/`). You can use the plus sign (`+`) and the forward slash (`/`) in the configuration file and on the command line.

***

### GENERAL OPTIONS

#### `AccelDir DIR`

Specify this option if using dynamic hardware acceleration and the engine implementation library resides somewhere other than the OpenSSL default. Can not be changed while Anon is running.

#### `AccelName NAME`

When using OpenSSL hardware crypto acceleration attempt to load the dynamic engine of this name. This must be used for any dynamic hardware engine. Names can be verified with the openssl engine command. Can not be changed while Anon is running.

If the engine name is prefixed with a "`!`", then Anon will exit if the engine cannot be loaded.

**`AlternateBridgeAuthority`**` ``[`*`nickname`*`] [`**`flags`**`]`` `*`ipv4address:port fingerprint`*

#### `AlternateDirAuthority [nickname] [flags] ipv4address:port fingerprint`

These options behave as [`DirAuthority`](#dirauthority-nickname-flags-ipv4address-dirport-fingerprint), but they replace fewer of the default directory authorities. Using [`AlternateDirAuthority`](#alternatedirauthority-nickname-flags-ipv4address-port-fingerprint) replaces the default Anon directory authorities, but leaves the default bridge authorities in place. Similarly, [`AlternateBridgeAuthority`](#alternatedirauthority-nickname-flags-ipv4address-port-fingerprint) replaces the default bridge authority, but leaves the directory authorities alone.

#### `AvoidDiskWrites 0|1`

If non-zero, try to write to disk less frequently than we would otherwise. This is useful when running on flash memory or other media that support only a limited number of writes. (Default: `0`)

#### `BandwidthBurst N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

Limit the maximum token bucket size (also known as the burst) to the given number of bytes in each direction. (Default: `1 GByte`)

#### `BandwidthRate N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

A token bucket limits the average incoming bandwidth usage on this node to the specified number of bytes per second, and the average outgoing bandwidth usage to that same value. If you want to run a relay in the public network, this needs to be at the very least 75 KBytes for a relay (that is, 600 kbits) or 50 KBytes for a bridge (400 kbits) — but of course, more is better; we recommend at least 250 KBytes (2 mbits) if possible. (Default: `1 GByte`)

Note that this option, and other bandwidth-limiting options, apply to TCP data only: They do not count TCP headers or DNS traffic.

Anon uses powers of two, not powers of ten, so 1 GByte is 1024\_1024\_1024 bytes as opposed to 1 billion bytes.

With this option, and in other options that take arguments in `bytes`, `KBytes`, and so on, other formats are also supported. Notably, "`KBytes`" can also be written as "`kilobytes`" or "`kb`"; "`MBytes`" can be written as "`megabytes`" or "`MB`"; "`kbits`" can be written as "`kilobits`"; and so forth. Case doesn’t matter. Anon also accepts "`byte`" and "`bit`" in the singular. The prefixes "`tera`" and "`T`" are also recognized. If no units are given, we default to bytes. To avoid confusion, we recommend writing "`bytes`" or "`bits`" explicitly, since it’s easy to forget that "`B`" means `bytes`, not `bits`.

#### `CacheDirectory DIR`

Store cached directory data in **`DIR`**. Can not be changed while Anon is running. (Default: uses the value of [`DataDirectory`](#datadirectory-dir).)

#### `CacheDirectoryGroupReadable 0|1|auto`

If this option is set to `0`, don’t allow the filesystem group to read the [`CacheDirectory`](#cachedirectory-dire). If the option is set to `1`, make the [`CacheDirectory`](#cachedirectory-dire) readable by the default **`GID`**. If the option is "`auto`", then we use the setting for [`DataDirectoryGroupReadable`](#datadirectorygroupreadable-0-or-1) when the [`CacheDirectory`](#cachedirectory-dire) is the same as the [`DataDirectory`](#datadirectory-dir), and `0` otherwise. (Default: `auto`)

#### `CircuitPriorityHalflife NUM`

If this value is set, we override the default algorithm for choosing which circuit’s cell to deliver or relay next. It is delivered first to the circuit that has the lowest weighted cell count, where cells are weighted exponentially according to this value (in seconds). If the value is `-1`, it is taken from the consensus if possible else it will fallback to the default value of `30`. Minimum: `1`, Maximum: `2147483647`. This can be defined as a float value. This is an advanced option; you generally shouldn’t have to mess with it. (Default: `-1`)

#### `ClientTransportPlugin transport socks4|socks5 IP:PORT`

#### `ClientTransportPlugin transport exec path-to-binary [options]`

In its first form, when set along with a corresponding [`Bridge`](#bridge-transport-ip-orport-fingerprint) line, the Anon client forwards its traffic to a **SOCKS**-speaking proxy on "`IP:PORT`". (IPv4 addresses should written as-is; IPv6 addresses should be wrapped in square brackets.) It’s the duty of that proxy to properly forward the traffic to the bridge.

In its second form, when set along with a corresponding [`Bridge`](#bridge-transport-ip-orport-fingerprint) line, the Anon client launches the pluggable transport proxy executable in path-to-binary using options as its command-line options, and forwards its traffic to it. It’s the duty of that proxy to properly forward the traffic to the bridge. (Default: `none`)

#### `ConfluxEnabled 0|1|auto`

If this option is set to `1`, general purpose traffic will use **Conflux** which is traffic splitting among multiple legs (circuits). Onion services are not supported at the moment. Default value is set to "`auto`" meaning the consensus is used to decide unless set. (Default: `auto`)

#### `ConfluxClientUX throughput|latency|throughput_lowmem|latency_lowmem`

This option configures the user experience that the client requests from the exit, for data that the exit sends to the client. The default is "`throughput`", which maximizes throughput. "`Latency`" will tell the exit to only use the circuit with lower latency for all data. The lowmem versions minimize queue usage memory at the client. (Default: "`throughput`")

#### `ConnLimit NUM`

The minimum number of file descriptors that must be available to the Anon process before it will start. Anon will ask the OS for as many file descriptors as the OS will allow (you can find this by "`ulimit -H -n`"). If this number is less than [`ConnLimit`](#connlimit-num), then Anon will refuse to start.

Anon relays need thousands of sockets, to connect to every other relay. If you are running a private bridge, you can reduce the number of sockets that Anon uses. For example, to limit Anon to `500` sockets, run "`ulimit -n 500`" in a shell. Then start Anon in the same shell, with `ConnLimit 500`. You may also need to set `DisableOOSCheck 0`.

Unless you have severely limited sockets, you probably don’t need to adjust [`ConnLimit`](#connlimit-num) itself. It has no effect on Windows, since that platform lacks **getrlimit()**. (Default: `1000`)

#### `ConstrainedSockets 0|1`

If set, Anon will tell the kernel to attempt to shrink the buffers for all sockets to the size specified in [`ConstrainedSockSize`](#constrainedsocksize-n-bytes-or-kbytes). This is useful for virtual servers and other environments where system level TCP buffers may be limited. If you’re on a virtual server, and you encounter the "**Error creating network socket: No buffer space available**" message, you are likely experiencing this problem.

The preferred solution is to have the admin increase the buffer pool for the host itself via `/proc/sys/net/ipv4/tcp_mem` or equivalent facility; this configuration option is a second-resort.

The `DirPort` option should also not be used if TCP buffers are scarce. The cached directory requests consume additional sockets which exacerbates the problem.

You should not enable this feature unless you encounter the "**no buffer space available**" issue. Reducing the TCP buffers affects window size for the TCP stream and will reduce throughput in proportion to round trip time on long paths. (Default: `0`)

#### `ConstrainedSockSize N bytes|KBytes`

When [`ConstrainedSockets`](#constrainedsockets-0-or-1) is enabled the receive and transmit buffers for all sockets will be set to this limit. Must be a value between `2048` and `262144`, in 1024 byte increments. Default of `8192` is recommended.

#### `ControlPort [address:]port|unix:path|auto [flags]`

If set, Anon will accept connections on this port and allow those connections to control the Anon process using the Anon Control Protocol (described in `control-spec.txt`). Note: unless you also specify one or more of [`HashedControlPassword`](#hashedcontrolpassword-hashed_password) or [`CookieAuthentication`](#cookieauthentication-0-or-1), setting this option will cause Anon to allow any process on the local host to control it. (Setting both authentication methods means either method is sufficient to authenticate to Anon.) This option is required for many Anon controllers; most use the value of `9051`. If a unix domain socket is used, you may quote the path using standard C escape sequences. You can specify this directive multiple times, to bind to multiple address/port pairs. Set it to "`auto`" to have Anon pick a port for you. (Default: `0`)

Recognized flags are:

#### `GroupWritable`

Unix domain sockets only: makes the socket get created as group-writable.

#### `WorldWritable`

Unix domain sockets only: makes the socket get created as world-writable.

#### `RelaxDirModeCheck`

Unix domain sockets only: Do not insist that the directory that holds the socket be read-restricted.

#### `ControlPortFileGroupReadable 0|1`

If this option is set to 0, don’t allow the filesystem group to read the control port file. If the option is set to 1, make the control port file readable by the default GID. (Default: `0`)

#### `ControlPortWriteToFile Path`

If set, Anon writes the address and port of any control port it opens to this address. Usable by controllers to learn the actual control port when [`ControlPort`](#controlport-address-port-or-unix-path-or-auto-flags) is set to "`auto`".

#### `ControlSocket Path`

Like [`ControlPort`](#controlport-address-port-or-unix-path-or-auto-flags), but listens on a Unix domain socket, rather than a TCP socket. 0 disables [`ControlSocket`](#controlsocket-path). (Unix and Unix-like systems only.) (Default: `0`)

#### `ControlSocketsGroupWritable 0|1`

If this option is set to 0, don’t allow the filesystem group to read and write unix sockets (e.g. [`ControlSocket`](#controlsocket-path)). If the option is set to 1, make the control socket readable and writable by the default GID. (Default: `0`)

#### `CookieAuthentication 0|1`

If this option is set to 1, allow connections on the control port when the connecting process knows the contents of a file named "`control_auth_cookie`", which Anon will create in its data directory. This authentication method should only be used on systems with good filesystem security. (Default: `0`)

#### `CookieAuthFile Path`

If set, this option overrides the default location and file name for Anon’s cookie file. (See [CookieAuthentication](#cookieauthentication-0-or-1).)

#### `CookieAuthFileGroupReadable 0|1`

If this option is set to `0`, don’t allow the filesystem group to read the cookie file. If the option is set to `1`, make the cookie file readable by the default GID. \[Making the file readable by other groups is not yet implemented; let us know if you need this for some reason.] (Default: `0`)

#### `CountPrivateBandwidth 0|1`

If this option is set, then Anon’s rate-limiting applies not only to remote connections, but also to connections to private addresses like `127.0.0.1` or `10.0.0.1`. This is mostly useful for debugging rate-limiting. (Default: `0`)

#### `DataDirectory DIR`

Store working data in DIR. Can not be changed while Anon is running. (Default: `~/.anon` if your home directory is not `/;` otherwise, `/var/lib/anon`. On Windows, the default is your ApplicationData folder.)

#### `DataDirectoryGroupReadable 0|1`

If this option is set to `0`, don’t allow the filesystem group to read the [`DataDirectory`](#datadirectory-dir). If the option is set to 1, make the [`DataDirectory`](#datadirectory-dir) readable by the default GID. (Default: 0)

#### `DirAuthority [nickname] [flags] ipv4address:dirport fingerprint`

Use a nonstandard authoritative directory server at the provided address and port, with the specified key fingerprint. This option can be repeated many times, for multiple authoritative directory servers. Flags are separated by spaces, and determine what kind of an authority this directory is. By default, an authority is not authoritative for any directory style or version unless an appropriate flag is given.

Anon will use this authority as a bridge authoritative directory if the "`bridge`" flag is set. If a flag "`orport=orport`" is given, Anon will use the given port when opening encrypted tunnels to the dirserver. If a flag "`weight=num`" is given, then the directory server is chosen randomly with probability proportional to that weight (default `1.0`). If a flag "`v3ident=fp`" is given, the dirserver is a v3 directory authority whose v3 long-term signing key has the fingerprint fp. Lastly, if an "`ipv6=[ipv6address]:orport`" flag is present, then the directory authority is listening for IPv6 connections on the indicated IPv6 address and OR Port.

Anon will contact the authority at ipv4address to download directory documents. Clients always use the [`ORPort`](#orport-address-port-or-auto-flags). Relays usually use the [`DirPort`](#dirport-address-port-or-auto-flags), but will use the [`ORPort`](#orport-address-port-or-auto-flags) in some circumstances. If an IPv6 [`ORPort`](#orport-address-port-or-auto-flags) is supplied, clients will also download directory documents at the IPv6 [`ORPort`](#orport-address-port-or-auto-flags), if they are configured to use IPv6.

If no [`DirAuthority`](#dirauthority-nickname-flags-ipv4address-dirport-fingerprint) line is given, Anon will use the default directory authorities. NOTE: this option is intended for setting up a private Anon network with its own directory authorities. If you use it, you will be distinguishable from other users, because you won’t believe the same authorities they do.

#### `DirAuthorityFallbackRate NUM`

When configured to use both directory authorities and fallback directories, the directory authorities also work as fallbacks. They are chosen with their regular weights, multiplied by this number, which should be 1.0 or less. The default is less than 1, to reduce load on authorities. (Default: `0.1`)

#### `DisableAllSwap 0|1`

If set to `1`, Anon will attempt to lock all current and future memory pages, so that memory cannot be paged out. Windows, OS X and Solaris are currently not supported. We believe that this feature works on modern Gnu/Linux distributions, and that it should work on \*BSD systems (untested). This option requires that you start your Anon as root, and you should use the User option to properly reduce Anon’s privileges. Can not be changed while Anon is running. (Default: `0`)

#### `DisableDebuggerAttachment 0|1`

If set to `1`, Anon will attempt to prevent basic debugging attachment attempts by other processes. This may also keep Anon from generating core files if it crashes. It has no impact for users who wish to attach if they have `CAP_SYS_PTRACE` or if they are root. We believe that this feature works on modern Gnu/Linux distributions, and that it may also work on \*BSD systems (untested). Some modern Gnu/Linux systems such as Ubuntu have the kernel.yama.ptrace\_scope sysctl and by default enable it as an attempt to limit the `PTRACE` scope for all user processes by default. This feature will attempt to limit the `PTRACE` scope for Anon specifically - it will not attempt to alter the system wide ptrace scope as it may not even exist. If you wish to attach to Anon with a debugger such as gdb or strace you will want to set this to `0` for the duration of your debugging. Normal users should leave it on. Disabling this option while Anon is running is prohibited. (Default: `1`)

#### `DisableNetwork 0|1`

When this option is set, we don’t listen for or accept any connections other than controller connections, and we close (and don’t reattempt) any outbound connections. Controllers sometimes use this option to avoid using the network until Anon is fully configured. Anon will make still certain network-related calls (like DNS lookups) as a part of its configuration process, even if [`DisableNetwork`](#disablenetwork-0-or-1) is set. (Default: `0`)

#### `ExtendByEd25519ID 0|1|auto`

If this option is set to 1, we always try to include a relay’s Ed25519 ID when telling the preceding relay in a circuit to extend to it. If this option is set to `0`, we never include Ed25519 IDs when extending circuits. If the option is set to "`auto`", we obey a parameter in the consensus document. (Default: `auto`)

#### `ExtORPort [address:]port|auto`

Open this port to listen for Extended ORPort connections from your pluggable transports.\
(Default: `DataDirectory/extended_orport_auth_cookie`)

#### `ExtORPortCookieAuthFile Path`

If set, this option overrides the default location and file name for the Extended ORPort’s cookie file — the cookie file is needed for pluggable transports to communicate through the Extended ORPort.

#### `ExtORPortCookieAuthFileGroupReadable 0|1`

If this option is set to `0`, don’t allow the filesystem group to read the Extended OR Port cookie file. If the option is set to `1`, make the cookie file readable by the default GID. \[Making the file readable by other groups is not yet implemented; let us know if you need this for some reason.] (Default: `0`)

#### `FallbackDir ipv4address:dirport orport=orport id=fingerprint [weight=num] [ipv6=[ipv6address]:orport]`

When Anon is unable to connect to any directory cache for directory info (usually because it doesn’t know about any yet) it tries a hard-coded directory. Relays try one directory authority at a time. Clients try multiple directory authorities and FallbackDirs, to avoid hangs on startup if a hard-coded directory is down. Clients wait for a few seconds between each attempt, and retry FallbackDirs more often than directory authorities, to reduce the load on the directory authorities.

FallbackDirs should be stable relays with stable IP addresses, ports, and identity keys. They must have a DirPort.

By default, the directory authorities are also FallbackDirs. Specifying a `FallbackDir` replaces Anon’s default hard-coded FallbackDirs (if any). (See [`DirAuthority`](#dirauthority-nickname-flags-ipv4address-dirport-fingerprint) for an explanation of each flag.)

#### `FetchDirInfoEarly 0|1`

If set to `1`, Anon will always fetch directory information like other directory caches, even if you don’t meet the normal criteria for fetching early. Normal users should leave it off. (Default: `0`)

#### `FetchDirInfoExtraEarly 0|1`

If set to `1`, Anon will fetch directory information before other directory caches. It will attempt to download directory information closer to the start of the consensus period. Normal users should leave it off. (Default: `0`)

#### `FetchHidServDescriptors 0|1`

If set to `0`, Anon will never fetch any hidden service descriptors from the rendezvous directories. This option is only useful if you’re using a Anon controller that handles hidden service fetches for you. (Default: `1`)

#### `FetchServerDescriptors 0|1`

If set to `0`, Anon will never fetch any network status summaries or server descriptors from the directory servers. This option is only useful if you’re using a Anon controller that handles directory fetches for you. (Default: `1`)

#### `FetchUselessDescriptors 0|1`

If set to `1`, Anon will fetch every consensus flavor, and all server descriptors and authority certificates referenced by those consensuses, except for extra info descriptors. When this option is `1`, Anon will also keep fetching descriptors, even when idle. If set to `0`, Anon will avoid fetching useless descriptors: flavors that it is not using to build circuits, and authority certificates it does not trust. When Anon hasn’t built any application circuits, it will go idle, and stop fetching descriptors. This option is useful if you’re using a Anon client with an external parser that uses a full consensus. This option fetches all documents except extrainfo descriptors, [`DirCache`](#dircache-0-or-1) fetches and serves all documents except extrainfo descriptors, [`DownloadExtraInfo`](#downloadextrainfo-0-or-1)`*` fetches extrainfo documents, and serves them if [`DirCache`](#dircache-0-or-1) is on, and [`UseMicrodescriptors`](#usemicrodescriptors-0-or-1-or-auto) changes the flavor of consensuses and descriptors that is fetched and used for building circuits. (Default: `0`)

#### `HardwareAccel 0|1`

If non-zero, try to use built-in (static) crypto hardware acceleration when available. Can not be changed while Anon is running. (Default: `0`)

#### `HashedControlPassword hashed_password`

Allow connections on the control port if they present the password whose one-way hash is hashed\_password. You can compute the hash of a password by running "`Anon --hash-password password`". You can provide several acceptable passwords by using more than one `HashedControlPassword` line.

#### `HTTPSProxy host[:port]`

Anon will make all its OR (SSL) connections through this `host:port` (or `host:443` if port is not specified), via `HTTP CONNECT` rather than connecting directly to servers. You may want to set [`FascistFirewall`](#fascistfirewall-0-or-1) to restrict the set of ports you might try to connect to, if your HTTPS proxy only allows connecting to certain ports.

#### `HTTPSProxyAuthenticator username:password`

If defined, Anon will use this `username:password` for Basic HTTPS proxy authentication, as in **RFC 2617**. This is currently the only form of HTTPS proxy authentication that Anon supports; feel free to submit a patch if you want it to support others.

#### `KeepalivePeriod NUM`

To keep firewalls from expiring connections, send a padding keepalive cell every `NUM` seconds on open connections that are in use. (Default: `5 minutes`)

#### `KeepBindCapabilities 0|1|auto`

On Linux, when we are started as root and we switch our identity using the User option, the `KeepBindCapabilities` option tells us whether to try to retain our ability to bind to low ports. If this value is `1`, we try to keep the capability; if it is `0` we do not; and if it is `auto`, we keep the capability only if we are configured to listen on a low port. Can not be changed while Anon is running. (Default: `auto`.)

#### `Log minSeverity[-maxSeverity] stderr|stdout|syslog`

Send all messages between `minSeverity` and `maxSeverity` to the standard output stream, the standard error stream, or to the system log. (The "**syslog**" value is only supported on Unix.) Recognized severity levels are **debug**, **info**, **notice**, **warn**, and **err**. We advise using "**notice**" in most cases, since anything more verbose may provide sensitive information to an attacker who obtains the logs. If only one severity level is given, all messages of that level or higher will be sent to the listed destination.

Some low-level logs may be sent from signal handlers, so their destination logs must be signal-safe. These low-level logs include **backtraces**, logging function errors, and errors in code called by logging functions. Signal-safe logs are always sent to stderr or **stdout**. They are also sent to a limited number of log files that are configured to log messages at error severity from the bug or general domains. They are never sent as **syslogs**, control port log events, or to any API-based log destinations.

#### `Log minSeverity[-maxSeverity] file`` `*`FILENAME`*

As above, but send log messages to the listed filename. The "**Log**" option may appear more than once in a configuration file. Messages are sent to all the logs that match their severity level.

**`Log [`***`domain`*`,...`**`]`***`minSeverity`*`[-`*`maxSeverity`*`]`` `**`... file`** *`FILENAME`*

#### `Log [domain,...]minSeverity[-maxSeverity] ... stderr|stdout|syslog`

As above, but select messages by range of log severity and by a set of "**logging domains**". Each logging domain corresponds to an area of functionality inside Anon. You can specify any number of severity ranges for a single log statement, each of them prefixed by a comma-separated list of logging domains. You can prefix a domain with `~` to indicate negation, and use `*` to indicate "**all domains**". If you specify a severity range without a list of domains, it matches all domains.

This is an advanced feature which is most useful for debugging one or two of Anon’s subsystems at a time.

The currently recognized domains are: **general**, **crypto**, **net**, **config**, **fs**, **protocol**, **mm**, **http**, **app**, **control**, **circ**, **rend**, **bug**, **dir**, **dirserv**, **or**, **edge**, **acct**, hist, handshake, **heartbeat**, **channel**, **sched**, **guard**, **consdiff**, **dos**, **process**, **pt**, **btrack**, and **mesg**. Domain names are case-insensitive.

For example, "`Log [handshake]debug [~net,~mm]info notice stdout`" sends to stdout: all handshake messages of any severity, all info-and-higher messages from domains other than networking and memory management, and all messages of severity notice or higher.

#### `LogMessageDomains 0|1`

If 1, Anon includes message domains with each log message. Every log message currently has at least one domain; most currently have exactly one. This doesn’t affect controller log messages. (Default: `0`)

#### `LogTimeGranularity NUM`

Set the resolution of timestamps in Anon’s logs to `NUM` milliseconds. `NUM` must be positive and either a divisor or a multiple of 1 second. Note that this option only controls the granularity written by Anon to a file or console log. Anon does not (for example) "**batch up**" log messages to affect times logged by a controller, times attached to syslog messages, or the mtime fields on log files. (Default: `1 second`)

#### `MaxAdvertisedBandwidth N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

If set, we will not advertise more than this amount of bandwidth for our [`BandwidthRate`](#bandwidthrate-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits). Server operators who want to reduce the number of clients who ask to build circuits through them (since this is proportional to advertised bandwidth rate) can thus reduce the CPU demands on their server without impacting network performance.

#### `MaxUnparseableDescSizeToLog N bytes|KBytes|MBytes|GBytes|TBytes`

Descriptors unable to be parsed (e.g. for votes, consensuses, routers) are logged in separate files by hash, up to the specified size in total. Note that only files logged during the lifetime of this Anon process count toward the total; this is intended to be used to debug problems without opening live servers to resource exhaustion attacks. (Default: `10 MBytes`)

#### `MetricsPort [address:]port [format]`

**WARNING**: Before enabling this, it is important to understand that exposing Anon metrics publicly is dangerous to the Anon network users. Please take extra precaution and care when opening this port. Set a very strict access policy with [`MetricsPortPolicy`](#metricsportpolicy-policy-policy) and consider using your operating systems firewall features for defense in depth.

We recommend, for the prometheus format, that the only address that can access this port should be the Prometheus server itself. Remember that the connection is unencrypted (HTTP) hence consider using a tool like stunnel to secure the link from this port to the server.

If set, open this port to listen for an HTTP GET request to "`/metrics`". Upon a request, the collected metrics in the the Anon instance are formatted for the given format and then sent back. If this is set, [`MetricsPortPolicy`](#metricsportpolicy-policy-policy) must be defined else every request will be rejected.

Supported format is "**prometheus**" which is also the default if not set. The Prometheus data model can be found here: <https://prometheus.io/docs/concepts/data_model/>

The Anon metrics are constantly collected and they solely consists of counters. Thus, asking for those metrics is very lightweight on the Anon process. (Default: `None`)

As an example, here only `5.6.7.8` will be allowed to connect:

**`MetricsPort 1.2.3.4:9035 MetricsPortPolicy accept 5.6.7.8`**

#### `MetricsPortPolicy policy,policy,...`

Set an entrance policy for the [`MetricsPort`](#metricsport-address-port-format), to limit who can access it. The policies have the same form as exit policies below, except that port specifiers are ignored. For multiple entries, this line can be used multiple times. It is a reject all by default policy. (Default: None)

Please, keep in mind here that if the server collecting metrics on the [`MetricsPort`](#metricsport-address-port-format) is behind a NAT, then everything behind it can access it. This is similar for the case of allowing localhost, every users on the server will be able to access it. Again, strongly consider using a tool like stunnel to secure the link or to strengthen access control.

#### `NoExec 0|1`

If this option is set to 1, then Anon will never launch another executable, regardless of the settings of [`ClientTransportPlugin`](#clienttransportplugin-transport-socks4-or-socks5-ip-port) or [`ServerTransportPlugin`](#servertransportlistenaddr-transport-ip-port). Once this option has been set to `1`, it cannot be set back to `0` without restarting Anon. (Default: `0`)

#### `OutboundBindAddress IP`

Make all outbound connections originate from the IP address specified. This is only useful when you have multiple network interfaces, and you want all of Anon’s outgoing connections to use a single one. This option may be used twice, once with an IPv4 address and once with an IPv6 address. IPv6 addresses should be wrapped in square brackets. This setting will be ignored for connections to the loopback addresses (`127.0.0.0/8` and `::1`), and is not used for DNS requests as well.

#### `OutboundBindAddressExit IP`

Make all outbound exit connections originate from the IP address specified. This option overrides [`OutboundBindAddress`](#outboundbindaddress-ip) for the same IP version. This option may be used twice, once with an IPv4 address and once with an IPv6 address. IPv6 addresses should be wrapped in square brackets. This setting will be ignored for connections to the loopback addresses (`127.0.0.0/8` and `::1`).

#### `OutboundBindAddressOR IP`

Make all outbound non-exit (relay and other) connections originate from the IP address specified. This option overrides [`OutboundBindAddress`](#outboundbindaddress-ip) for the same IP version. This option may be used twice, once with an IPv4 address and once with an IPv6 address. IPv6 addresses should be wrapped in square brackets. This setting will be ignored for connections to the loopback addresses (`127.0.0.0/8` and `::1`).

#### `OwningControllerProcess PID`

Make Anon instance periodically check for presence of a controller process with given PID and terminate itself if this process is no longer alive. Polling interval is 15 seconds.

#### `PerConnBWBurst N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

If this option is set manually, or via the "**perconnbwburst**" consensus field, Anon will use it for separate rate limiting for each connection from a non-relay. (Default: `0`)

#### `PerConnBWRate N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

If this option is set manually, or via the "**perconnbwrate**" consensus field, Anon will use it for separate rate limiting for each connection from a non-relay. (Default: `0`)

#### `OutboundBindAddressPT IP`

Request that pluggable transports makes all outbound connections originate from the IP address specified. Because outgoing connections are handled by the pluggable transport itself, it is not possible for Anon to enforce whether the pluggable transport honors this option. This option overrides [`OutboundBindAddress`](broken://pages/UIyPFxnnhIyxceeUt1y2#outboundbindaddress-ip) for the same IP version. This option may be used twice, once with an IPv4 address and once with an IPv6 address. IPv6 addresses should be wrapped in square brackets. This setting will be ignored for connections to the loopback addresses (`127.0.0.0/8` and `::1`).

#### `PidFile FILE`

On startup, write our `PID` to `FILE`. On clean shutdown, remove `FILE`. Can not be changed while Anon is running.

#### `ProtocolWarnings 0|1`

If 1, Anon will log with severity '**warn**' various cases of other parties not following the Anon specification. Otherwise, they are logged with severity '**info**'. (Default: `0`)

#### `RelayBandwidthBurst N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

If not 0, limit the maximum token bucket size (also known as the burst) for *relayed traffic* to the given number of bytes in each direction. They do not include directory fetches by the relay (from authority or other relays), because that is considered "client" activity. (Default: `0`) [`RelayBandwidthBurst`](broken://pages/UIyPFxnnhIyxceeUt1y2#bandwidthburst-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1) defaults to the value of [`RelayBandwidthRate`](broken://pages/UIyPFxnnhIyxceeUt1y2#bandwidthrate-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1) if unset.

#### `RelayBandwidthRate N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

If not 0, a separate token bucket limits the average incoming bandwidth usage for *relayed traffic* on this node to the specified number of bytes per second, and the average outgoing bandwidth usage to that same value. Relayed traffic currently is calculated to include answers to directory requests, but that may change in future versions. They do not include directory fetches by the relay (from authority or other relays), because that is considered "client" activity. (Default: `0`) [`RelayBandwidthRate`](broken://pages/UIyPFxnnhIyxceeUt1y2#bandwidthrate-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1) defaults to the value of [`RelayBandwidthBurst`](broken://pages/UIyPFxnnhIyxceeUt1y2#bandwidthburst-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1) if unset.

#### `RephistTrackTime N seconds|minutes|hours|days|weeks`

Tells an authority, or other node tracking node reliability and history, that fine-grained information about nodes can be discarded when it hasn’t changed for a given amount of time. (Default: `24 hours`)

#### `RunAsDaemon 0|1`

If 1, Anon forks and daemonizes to the background. This option has no effect on Windows; instead you should use the `--service` command-line option. Can not be changed while Anon is running. (Default: `0`)

#### `SafeLogging 0|1|relay`

Anon can scrub potentially sensitive strings from log messages (e.g. addresses) by replacing them with the string \[scrubbed]. This way logs can still be useful, but they don’t leave behind personally identifying information about what sites a user might have visited.

If this option is set to 0, Anon will not perform any scrubbing, if it is set to 1, all potentially sensitive strings are replaced. If it is set to relay, all log messages generated when acting as a relay are sanitized, but all messages generated when acting as a client are not. Note: Anon may not heed this option when logging at log levels below Notice. (Default: `1`)

#### `Sandbox 0|1`

If set to 1, Anon will run securely through the use of a **syscall** sandbox. Otherwise the sandbox will be disabled. The option only works on Linux-based operating systems, and only when Anon has been built with the **libseccomp** library. Note that this option may be incompatible with some versions of **libc**, and some kernel versions. This option can not be changed while Anon is running.

When the `Sandbox` is 1, the following options can not be changed when Anon is running: `Address`, [`ConnLimit`](broken://pages/UIyPFxnnhIyxceeUt1y2#connlimit-num), [`CookieAuthFile`](broken://pages/UIyPFxnnhIyxceeUt1y2#cookieauthfile-path), [`DirPortFrontPage`](broken://pages/UIyPFxnnhIyxceeUt1y2#dirportfrontpage-filename), [`ExtORPortCookieAuthFile`](broken://pages/UIyPFxnnhIyxceeUt1y2#extorportcookieauthfile-path), [`Logs`](#log-minseverity-maxseverity-file-filename), [`ServerDNSResolvConfFile`](#serverdnsresolvconffile-filename), [`ClientOnionAuthDir`](#clientonionauthdir-path) (and any files in it won’t reload on HUP signal).

Launching new Onion Services through the control port is not supported with current syscall sandboxing implementation.

Anon must remain in client or server mode (some changes to [`ClientOnly`](#clientonly-0-or-1) and [`ORPort`](#orport-address-port-or-auto-flags) are not allowed). Currently, if `Sandbox` is `1`, [`ControlPort`](#controlport-address-port-or-unix-path-or-auto-flags) command "`GETINFO address`" will not work.

When using `%include` in the Anon configuration files, reloading the Anon configuration is not supported after adding new configuration files or directories.(Default: `0`)

#### `Schedulers KIST|KISTLite|Vanilla`

Specify the scheduler type that Anon should use. The scheduler is responsible for moving data around within a Anon process. This is an ordered list by priority which means that the first value will be tried first and if unavailable, the second one is tried and so on. It is possible to change these values at runtime. This option mostly effects relays, and most operators should leave it set to its default value. (Default: `KIST,KISTLite,Vanilla`)

The possible scheduler types are:

`KIST`: Kernel-Informed Socket Transport. Anon will use TCP information from the kernel to make informed decisions regarding how much data to send and when to send it. `KIST` also handles traffic in batches (see [`KISTSchedRunInterval`](#kistschedruninterval-num-msec)) in order to improve traffic prioritization decisions. As implemented, `KIST` will only work on Linux kernel version 2.6.39 or higher.

`KISTLite`: Same as `KIST` but without kernel support. Anon will use all the same mechanics as with `KIST`, including the batching, but its decisions regarding how much data to send will not be as good. `KISTLite` will work on all kernels and operating systems, and the majority of the benefits of `KIST` are still realized with `KISTLite`.

`Vanilla`: The scheduler that Anon used before `KIST` was implemented. It sends as much data as possible, as soon as possible. `Vanilla` will work on all kernels and operating systems.

#### `KISTSchedRunInterval NUM msec`

If `KIST` or `KISTLite` is used in the [`Schedulers`](#schedulers-kist-or-kistlite-or-vanilla) option, this controls at which interval the scheduler tick is. If the value is `0 msec`, the value is taken from the consensus if possible else it will fallback to the default `10 msec`. Maximum possible value is `100 msec`. (Default: `0 msec`)

#### `KISTSockBufSizeFactor NUM`

If `KIST` is used in [`Schedulers`](#schedulers-kist-or-kistlite-or-vanilla), this is a multiplier of the per-socket limit calculation of the `KIST` algorithm. (Default: `1.0`)

#### `Socks4Proxy host[:port]`

Anon will make all OR connections through the SOCKS 4 proxy at `host:port` (or `host:1080` if port is not specified).

#### `Socks5Proxy host[:port]`

Anon will make all OR connections through the SOCKS 5 proxy at `host:port` (or `host:1080` if port is not specified).

#### `Socks5ProxyUsername username`

#### `Socks5ProxyPassword password`

If defined, authenticate to the SOCKS 5 server using username and password in accordance to **RFC 1929**. Both username and password must be between `1` and `255` characters.

#### `SyslogIdentityTag tag`

When logging to syslog, adds a tag to the syslog identity such that log entries are marked with "**Anon-tag**". Can not be changed while Anon is running. (Default: `none`)

#### `TCPProxy protocol host:port`

Anon will use the given protocol to make all its OR (**SSL**) connections through a TCP proxy on `host:port`, rather than connecting directly to servers. You may want to set [`FascistFirewall`](#fascistfirewall-0-or-1) to restrict the set of ports you might try to connect to, if your proxy only allows connecting to certain ports. There is no equivalent option for directory connections, because all Anon client versions that support this option download directory documents via OR connections.

The only protocol supported right now '**haproxy**'. This option is only for clients. (Default: `none`) +

The HAProxy version 1 proxy protocol is described in detail at <https://www.haproxy.org/download/1.8/doc/proxy-protocol.txt> +

Both source IP address and source port will be set to zero.

#### `TruncateLogFile 0|1`

If `1`, Anon will overwrite logs at startup and in response to a HUP signal, instead of appending to them. (Default: `0`)

#### `UnixSocksGroupWritable 0|1`

If this option is set to `0`, don’t allow the filesystem group to read and write unix sockets (e.g. `SocksPort unix:`). If the option is set to `1`, make the Unix socket readable and writable by the default GID. (Default: 0)

#### `UseDefaultFallbackDirs 0|1`

Use Anon’s default hard-coded **FallbackDirs** (if any). (When a [`FallbackDir`](#fallbackdir-ipv4address-dirport-orport-orport-id-fingerprint-weight-num-ipv6-ipv6address-orport) line is present, it replaces the hard-coded **FallbackDirs**, regardless of the value of `UseDefaultFallbackDirs`.) (Default: `1`)

User Username On startup, `setuid` to this user and `setgid` to their primary group. Can not be changed while Anon is running.

***

### SERVER OPTIONS

The following options are useful only for servers (that is, if [`ORPort`](#orport-address-port-or-auto-flags) is non-zero):

#### `AccountingMax N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

Limits the max number of bytes sent and received within a set time period using a given calculation rule (see [**`AccountingStart`**](#accountingstart-day-or-week-or-month-day-hh-mm) and [**`AccountingRule`**](#accountingrule-sum-or-max-or-in-or-out)). Useful if you need to stay under a specific bandwidth. By default, the number used for calculation is the max of either the bytes sent or received. For example, with [`AccountingMax`](#accountingmax-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits) set to `1 TByte`, a server could send 900 GBytes and receive 800 GBytes and continue running. It will only hibernate once one of the two reaches 1 TByte. This can be changed to use the sum of the both bytes received and sent by setting the [`AccountingRule`](#accountingrule-sum-or-max-or-in-or-out-1) option to "`sum`" (total bandwidth in/out). When the number of bytes remaining gets low, Anon will stop accepting new connections and circuits. When the number of bytes is exhausted, Anon will hibernate until some time in the next accounting period. To prevent all servers from waking at the same time, Anon will also wait until a random point in each period before waking up. If you have bandwidth cost issues, enabling hibernation is preferable to setting a low bandwidth, since it provides users with a collection of fast servers that are up some of the time, which is more useful than a set of slow servers that are always "available".

Note that (as also described in the [Bandwidth section](#bandwidthburst-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits-1)) Anon uses powers of two, not powers of ten: `1 GByte` is **1024\_1024\_1024**, not one billion. Be careful: some internet service providers might count GBytes differently.

#### `AccountingRule sum|max|in|out`

How we determine when our [**`AccountingMax`**](#accountingmax-n-bytes-or-kbytes-or-mbytes-or-gbytes-or-tbytes-or-kbits-or-mbits-or-gbits-or-tbits) has been reached (when we should hibernate) during a time interval. Set to "`max`" to calculate using the higher of either the sent or received bytes (this is the default functionality). Set to "`sum`" to calculate using the sent plus received bytes. Set to "`in`" to calculate using only the received bytes. Set to "`out`" to calculate using only the sent bytes. (Default: `max`)

#### `AccountingStart day|week|month [day] HH:MM`

Specify how long accounting periods last. If month is given, each accounting period runs from the time `HH:MM` on the dayth day of one month to the same day and time of the next. The relay will go at full speed, use all the quota you specify, then hibernate for the rest of the period. (The day must be between `1` and `28`.) If week is given, each accounting period runs from the time `HH:MM` of the dayth day of one week to the same day and time of the next week, with Monday as day 1 and Sunday as day 7. If day is given, each accounting period runs from the time `HH:MM` each day to the same time on the next day. All times are local, and given in 24-hour time. (Default: `"month 1 0:00"`)

#### `Address address`

The address of this server, or a fully qualified domain name of this server that resolves to an address. You can leave this unset, and Anon will try to guess your address. If a domain name is provided, Anon will attempt to resolve it and use the underlying IPv4/IPv6 address as its publish address (taking precedence over the [`ORPort`](#orport-address-port-or-auto-flags) configuration). The publish address is the one used to tell clients and other servers where to find your Anon server; it doesn’t affect the address that your server binds to. To bind to a different address, use the [`ORPort`](#orport-address-port-or-auto-flags) and [`OutboundBindAddress`](#outboundbindaddress-ip) options.

#### `AddressDisableIPv6 0|1`

By default, Anon will attempt to find the IPv6 of the relay if there is no [IPv4Only](#ipv4only) [`ORPort`](#orport-address-port-or-auto-flags). If set, this option disables IPv6 auto discovery. This disables IPv6 address resolution, IPv6 ORPorts, and IPv6 reachability checks. Also, the relay won’t publish an IPv6 [`ORPort`](#orport-address-port-or-auto-flags) in its descriptor. (Default: `0`)

#### `AssumeReachable 0|1`

This option is used when bootstrapping a new Anon network. If set to `1`, don’t do self-reachability testing; just upload your server descriptor immediately. (Default: `0`)

#### `AssumeReachableIPv6 0|1|auto`

Like [`AssumeReachable`](#assumereachable-0-or-1), but affects only the relay’s own IPv6 [`ORPort`](#orport-address-port-or-auto-flags). If this value is set to "`auto`", then Anon will look at [`AssumeReachable`](#assumereachable-0-or-1) instead. (Default: `auto`)

#### `BridgeRelay 0|1`

Sets the relay to act as a "**bridge**" with respect to relaying connections from bridge users to the Anon network. It mainly causes Anon to publish a server descriptor to the bridge database, rather than to the public directory authorities.

Note: make sure that no [`MyFamily`](#myfamily-fingerprint-fingerprint-1) lines are present in your [anonrc ](#f-anonrc-file-file)when relay is configured in bridge mode.

#### `BridgeDistribution string`

If set along with [`BridgeRelay`](#bridgerelay-0-or-1), Anon will include a new line in its bridge descriptor which indicates to the **BridgeDB service** how it would like its bridge address to be given out. Set it to "`none`" if you want **BridgeDB** to avoid distributing your bridge address, or "`any`" to let **BridgeDB** decide.

#### `ContactInfo email_address`

Administrative contact information for this relay or bridge. This line can be used to contact you if your relay or bridge is misconfigured or something else goes wrong. Note that we archive and publish all descriptors containing these lines and that Google indexes them, so spammers might also collect them. You may want to obscure the fact that it’s an email address and/or generate a new address for this purpose.

`ContactInfo` must be set to a working address if you run more than one relay or bridge. (**Really, everybody running a relay or bridge should set it**.)

#### `DisableOOSCheck 0|1`

This option disables the code that closes connections when Anon notices that it is running low on sockets. Right now, it is on by default, since the existing out-of-sockets mechanism tends to kill OR connections more than it should. (Default: `1`)

#### `ExitPolicy policy,policy,...`

Set an exit policy for this server. Each policy is of the form "**`accept[6]|reject[6]`**` ``ADDR[/MASK][:PORT]`". If `/MASK` is omitted then this policy just applies to the host given. Instead of giving a host or network you can also use "`*`" to denote the universe (`0.0.0.0/0` and `::/0`), or *`4` to denote all IPv4 addresses, and `6` to denote all IPv6 addresses. `PORT` can be a single port number, an interval of ports "`FROM_PORT-TO_PORT`", or "". If `PORT` is omitted, that means "*".

For example, "`accept 18.7.22.69:`*`,reject 18.0.0.0/8:`*`,accept`` `*`:`*" would reject any IPv4 traffic destined for **MIT** except for **web.mit.edu**, and accept any other IPv4 or IPv6 traffic.

Anon also allows IPv6 exit policy entries. For instance, "`reject6 [FC00::]/7:`*" rejects all destinations that share 7 most significant bit prefix with address `FC00::`. Respectively, "`accept6 [C000::]/3:`*" accepts all destinations that share 3 most significant bit prefix with address `C000::`.

`accept6` and `reject6` only produce IPv6 exit policy entries. Using an IPv4 address with `accept6` or `reject6` is ignored and generates a warning. accept/reject allows either IPv4 or IPv6 addresses. Use `*4` as an IPv4 wildcard address, and `*6` as an IPv6 wildcard address. `accept/reject *` expands to matching IPv4 and IPv6 wildcard address rules.

To specify all IPv4 and IPv6 internal and link-local networks (including `0.0.0.0/8`, `169.254.0.0/16`, `127.0.0.0/8`, `192.168.0.0/16`, `10.0.0.0/8`, `172.16.0.0/12`, `[::]/8`, `[FC00::]/7`, `[FE80::]/10`, `[FEC0::]/10`, `[FF00::]/8`, and `[::]/127`), you can use the "`private`" alias instead of an address. ("`private`" always produces rules for IPv4 and IPv6 addresses, even when used with accept6/reject6.)

Private addresses are rejected by default (at the beginning of your exit policy), along with any configured primary public IPv4 and IPv6 addresses. These private addresses are rejected unless you set the [`ExitPolicyRejectPrivate`](#exitpolicyrejectprivate-0-or-1) config option to `0`. For example, once you’ve done that, you could allow HTTP to `127.0.0.1` and block all other connections to internal networks with "`accept 127.0.0.1:80,reject private:`\*", though that may also allow connections to your own computer that are addressed to its public (external) IP address. See **RFC 1918** and **RFC 3330** for more details about internal and reserved IP address space. See [`ExitPolicyRejectLocalInterfaces`](#exitpolicyrejectlocalinterfaces-0-or-1) if you want to block every address on the relay, even those that aren’t advertised in the descriptor.

This directive can be specified multiple times so you don’t have to put it all on one line.

Policies are considered first to last, and the first match wins. If you want to allow the same ports on IPv4 and IPv6, write your rules using `accept`/`reject *`. If you want to allow different ports on IPv4 and IPv6, write your IPv6 rules using `accept6`/`reject6 *6`, and your IPv4 rules using `accept`/`reject *4`. If you want to *replace* the default exit policy, end your exit policy with either a `reject`` `*`:`* or an `accept`` `*`:`*. Otherwise, you’re *augmenting* (prepending to) the default exit policy.

If you want to use a reduced exit policy rather than the default exit policy, set "[`ReducedExitPolicy`](#reducedexitpolicy-0-or-1) `1`". If you want to replace the default exit policy with your custom exit policy, end your exit policy with either a `reject :` or an `accept :`. Otherwise, you’re augmenting (prepending to) the default or reduced exit policy.

The default exit policy is:

`reject *:25 reject *:119 reject *:135-139 reject *:445 reject *:563 reject *:1214 reject *:4661-4666 reject *:6346-6429 reject *:6699 reject *:6881-6999 accept`` `*`:`*

Since the default exit policy uses `accept`/`reject *`, it applies to both IPv4 and IPv6 addresses.

#### `ExitPolicyRejectLocalInterfaces 0|1`

Reject all IPv4 and IPv6 addresses that the relay knows about, at the beginning of your exit policy. This includes any [`OutboundBindAddress`](#outboundbindaddress-ip), the bind addresses of any port options, such as [`ControlPort`](#controlport-address-port-or-unix-path-or-auto-flags) or [`DNSPort`](#dnsport-address-port-or-auto-isolation-flags), and any public IPv4 and IPv6 addresses on any interface on the relay. (If [`IPv6Exit`](#ipv6exit-0-or-1) is not set, all IPv6 addresses will be rejected anyway.) See above entry on [`ExitPolicy`](#exitpolicy-policy-policy). This option is off by default, because it lists all public relay IP addresses in the [`ExitPolicy`](#exitpolicy-policy-policy), even those relay operators might prefer not to disclose. (Default: `0`)

#### `ExitPolicyRejectPrivate 0|1`

Reject all private (local) networks, along with the relay’s advertised public IPv4 and IPv6 addresses, at the beginning of your exit policy. See above entry on [`ExitPolicy`](#exitpolicy-policy-policy). (Default: `1`)

#### `ExitRelay 0|1|auto`

Tells Anon whether to run as an exit relay. If Anon is running as a non-bridge server, and [`ExitRelay`](#exitrelay-0-or-1-or-auto) is set to `1`, then Anon allows traffic to exit according to the [`ExitPolicy`](#exitpolicy-policy-policy) option, the [`ReducedExitPolicy`](#reducedexitpolicy-0-or-1) option, or the default [`ExitPolicy`](#exitpolicy-policy-policy) (if no other exit policy option is specified).

If [`ExitRelay`](#exitrelay-0-or-1-or-auto) is set to `0`, no traffic is allowed to exit, and the [`ExitPolicy`](#exitpolicy-policy-policy), [`ReducedExitPolicy`](#reducedexitpolicy-0-or-1), and [`IPv6Exit`](#ipv6exit-0-or-1) options are ignored.

If [`ExitRelay`](#exitrelay-0-or-1-or-auto) is set to "`auto`", then Anon checks the [`ExitPolicy`](#exitpolicy-policy-policy), [`ReducedExitPolicy`](#reducedexitpolicy-0-or-1), and [`IPv6Exit`](#ipv6exit-0-or-1) options. If at least one of these options is set, Anon behaves as if [`ExitRelay`](#exitrelay-0-or-1-or-auto) were set to `1`. If none of these exit policy options are set, Anon behaves as if [`ExitRelay`](#exitrelay-0-or-1-or-auto) were set to `0`. (Default: `auto`)

#### `ReevaluateExitPolicy 0|1`

If set, reevaluate the exit policy on existing connections when reloading configuration.

When the exit policy of an exit node change while reloading configuration, connections made prior to this change could violate the new policy. By setting this to `1`, Anon will check if such connections exist, and mark them for termination. (Default: `0`)

#### `ExtendAllowPrivateAddresses 0|1`

When this option is **enabled**, Anon will connect to relays on localhost, **RFC 1918** addresses, and so on. In particular, Anon will make direct OR connections, and Anon routers allow `EXTEND` requests, to these private addresses. (Anon will always allow connections to **bridges**, **proxies**, and **pluggable transports** configured on private addresses.) Enabling this option can create security issues; you should probably leave it off. (Default: `0`)

`GeoIPFile filename` A filename containing IPv4 GeoIP data, for use with by-country statistics.

`GeoIPv6File filename` A filename containing IPv6 GeoIP data, for use with by-country statistics.

#### `HeartbeatPeriod N minutes|hours|days|weeks`

Log a heartbeat message every [`HeartbeatPeriod`](#heartbeatperiod-n-minutes-or-hours-or-days-or-weeks) seconds. This is a log level notice message, designed to let you know your Anon server is still alive and doing useful things. Settings this to `0` will disable the heartbeat. Otherwise, it **must be at least `30 minutes`**. (Default: `6 hours`)

#### `IPv6Exit 0|1`

If set, and we are an **exit** node, allow clients to use us for IPv6 traffic. When this option is set and [`ExitRelay`](#exitrelay-0-or-1-or-auto) is `auto`, we act as if [`ExitRelay`](#exitrelay-0-or-1-or-auto) is `1`. (Default: `0`)

#### `KeyDirectory DIR`

Store secret keys in `DIR`. Can not be changed while Anon is running. (Default: the "**`keys`**" subdirectory of [`DataDirectory`](#datadirectory-dir).)

#### `KeyDirectoryGroupReadable 0|1|auto`

If this option is set to `0`, don’t allow the filesystem group to read the [`KeyDirectory`](#keydirectory-dir). If the option is set to `1`, make the [`KeyDirectory`](#keydirectory-dir) readable by the default `GID`. If the option is "`auto`", then we use the setting for [`DataDirectoryGroupReadable`](#datadirectorygroupreadable-0-or-1) when the [`KeyDirectory`](#keydirectory-dir) is the same as the [`DataDirectory`](#datadirectory-dir), and `0` otherwise. (Default: `auto`)

#### `MainloopStats 0|1`

Log main loop statistics every [`HeartbeatPeriod`](#heartbeatperiod-n-minutes-or-hours-or-days-or-weeks) seconds. This is a log level notice message designed to help developers instrumenting Anon’s main event loop. (Default: `0`)

#### `MaxMemInQueues N bytes|KBytes|MBytes|GBytes`

This option configures a threshold above which Anon will assume that it needs to stop queueing or buffering data because it’s about to run out of memory. If it hits this threshold, it will begin killing circuits until it has recovered at least **10%** of this memory. Do not set this option too low, or your relay may be unreliable under load. This option only affects some queues, so the actual process size will be larger than this. If this option is set to `0`, Anon will try to pick a reasonable default based on your system’s physical memory. (Default: `0`)

#### `MaxOnionQueueDelay NUM [msec|second]`&#x20;

If we have more onionskins queued for processing than we can process in this amount of time, reject new ones. (Default: `1750 msec`)

#### `MyFamily fingerprint,fingerprint,...`

Declare that this Anon relay is controlled or administered by a group or organization identical or similar to that of the other relays, defined by their (possibly `$`-prefixed) identity fingerprints. **This option can be repeated many times**, for convenience in defining large families: all fingerprints in all `MyFamily` lines are merged into one list. When two relays both declare that they are in the same '**family**', Anon clients will not use them in the same circuit. (Each relay only needs to list the other servers in its family; it doesn’t need to list itself, but it won’t hurt if it does.) **Do not list any bridge relay as it would compromise its concealment**.

If you run more than one relay, the `MyFamily` option on each relay **must** list all other relays, as described above.

{% hint style="warning" %}
Do not use [`MyFamily`](#myfamily-fingerprint-fingerprint-1) when configuring your Anon instance as a [Bridge](#bridgerelay-0-or-1).
{% endhint %}

#### **`Nickname name`**

Set the server’s nickname to '`name`'. Nicknames must be between `1` and `19` characters inclusive, and must contain only the characters **\[a-zA-Z0-9]**. If not set, `Unnamed` will be used. Relays can always be uniquely identified by their identity fingerprints.

#### `NumCPUs num`

How many processes to use at once for decrypting onionskins and other parallelizable operations. If this is set to `0`, Anon will try to detect how many CPUs you have, defaulting to `1` if it can’t tell. (Default: `0`)

#### `OfflineMasterKey 0|1`

If **non-zero**, the Anon relay will never generate or load its master secret key. Instead, you’ll have to use "`anon --keygen`" to manage the permanent **ed25519** master identity key, as well as the corresponding temporary signing keys and certificates. (Default: `0`)

#### `ORPort [address:]PORT|auto [flags]`

Advertise this port to listen for connections from Anon clients and servers. This option is required to be a Anon server. Set it to "`auto`" to have Anon pick a port for you. Set it to `0` to not run an [`ORPort`](#orport-address-port-or-auto-flags) at all. This option can occur more than once. (Default: `0`)

Anon recognizes these flags on each [`ORPort`](#orport-address-port-or-auto-flags):

#### `NoAdvertise`

By default, we bind to a port and tell our users about it. If `NoAdvertise` is specified, we don’t advertise, but listen anyway. This can be useful if the port everybody will be connecting to (for example, one that’s opened on our firewall) is somewhere else.

#### `NoListen`

By default, we bind to a port and tell our users about it. If `NoListen` is specified, we don’t bind, but advertise anyway. This can be useful if something else (for example, a firewall’s port forwarding configuration) is causing connections to reach us.

#### `IPv4Only`

If the address is absent, or resolves to both an IPv4 and an IPv6 address, only listen to the IPv4 address.

#### `IPv6Only`

If the address is absent, or resolves to both an IPv4 and an IPv6 address, only listen to the IPv6 address.

For obvious reasons, [`NoAdvertise`](#noadvertise) and [`NoListen`](#nolisten) are mutually exclusive, and [`IPv4Only`](#ipv4only) and [`IPv6Only`](#ipv6only) are mutually exclusive.

#### `PublishServerDescriptor 0|1|v3|bridge,...`

This option specifies which descriptors Anon will publish when acting as a relay. You can choose multiple arguments, separated by commas.

If this option is set to `0`, Anon will not publish its descriptors to any directories. (This is useful if you’re testing out your server, or if you’re using a Anon controller that handles directory publishing for you.) Otherwise, Anon will publish its descriptors of all type(s) specified. The default is "`1`", which means "if running as a relay or bridge, publish descriptors to the appropriate authorities". Other possibilities are "`v3`", meaning "publish as if you’re a relay", and "`bridge`", meaning "publish as if you’re a bridge".

#### `ReducedExitPolicy 0|1`

If set, use a reduced exit policy rather than the default one.

The reduced exit policy is an alternative to the default exit policy. It allows as many Internet services as possible while still blocking the majority of TCP ports. Currently, the policy allows approximately 65 ports. This reduces the odds that your node will be used for peer-to-peer applications.

The reduced exit policy is:

`accept *:20-21 accept *:22 accept *:23 accept *:43 accept *:53 accept *:79 accept *:80-81 accept *:88 accept *:110 accept *:143 accept *:194 accept *:220 accept *:389 accept *:443 accept *:464 accept *:465 accept *:531 accept *:543-544 accept *:554 accept *:563 accept *:587 accept *:636 accept *:706 accept *:749 accept *:873 accept *:902-904 accept *:981 accept *:989-990 accept *:991 accept *:992 accept *:993 accept *:994 accept *:995 accept *:1194 accept *:1220 accept *:1293 accept *:1500 accept *:1533 accept *:1677 accept *:1723 accept *:1755 accept *:1863 accept *:2082 accept *:2083 accept *:2086-2087 accept *:2095-2096 accept *:2102-2104 accept *:3128 accept *:3389 accept *:3690 accept *:4321 accept *:4643 accept *:5050 accept *:5190 accept *:5222-5223 accept *:5228 accept *:5900 accept *:6660-6669 accept *:6679 accept *:6697 accept *:8000 accept *:8008 accept *:8074 accept *:8080 accept *:8082 accept *:8087-8088 accept *:8232-8233 accept *:8332-8333 accept *:8443 accept *:8888 accept *:9418 accept *:9999 accept *:10000 accept *:11371 accept *:19294 accept *:19638 accept *:50002 accept *:64738 reject`` `*`:`*

(Default: `0`)

#### `RefuseUnknownExits 0|1|auto`

Prevent nodes that don’t appear in the consensus from exiting using this relay. If the option is `1`, we always block exit attempts from such nodes; if it’s `0`, we never do, and if the option is "`auto`", then we do whatever the authorities suggest in the consensus (and block if the consensus is quiet on the issue). (Default: `auto`)

#### `ServerDNSAllowBrokenConfig 0|1`

If this option is false, Anon exits immediately if there are problems parsing the system DNS configuration or connecting to nameservers. Otherwise, Anon continues to periodically retry the system nameservers until it eventually succeeds. (Default: `1`)

#### `ServerDNSAllowNonRFC953Hostnames 0|1`

When this option is disabled, Anon does not try to resolve hostnames containing illegal characters (like `@` and `:`) rather than sending them to an exit node to be resolved. This helps trap accidental attempts to resolve URLs and so on. This option only affects name lookups that your server does on behalf of clients. (Default: `0`)

#### `ServerDNSDetectHijacking 0|1`

When this option is set to `1`, we will test periodically to determine whether our local nameservers have been configured to hijack failing DNS requests (usually to an advertising site). If they are, we will attempt to correct this. This option only affects name lookups that your server does on behalf of clients. (Default: `1`)

#### `ServerDNSRandomizeCase 0|1`

When this option is set, Anon sets the case of each character randomly in outgoing DNS requests, and makes sure that the case matches in DNS replies. This so-called "**0x20 hack**" helps resist some types of DNS poisoning attack. For more information, see "[Increased DNS Forgery Resistance through 0x20-Bit Encoding](https://astrolavos.gatech.edu/articles/increased_dns_resistance.pdf)". This option only affects name lookups that your server does on behalf of clients. (Default: `1`)

#### `ServerDNSResolvConfFile filename`

Overrides the default DNS configuration with the configuration in filename. The file format is the same as the standard Unix "`resolv.conf`" file (`7`). This option, like all other ServerDNS options, only affects name lookups that your server does on behalf of clients. (Defaults to use the system DNS configuration or a localhost DNS service in case no nameservers are found in a given configuration.)

#### `ServerDNSSearchDomains 0|1`

If set to `1`, then we will search for addresses in the local search domain. For example, if this system is configured to believe it is in "`example.com`", and a client tries to connect to "`www`", the client will be connected to "`www.example.com`". This option only affects name lookups that your server does on behalf of clients. (Default: `0`)

#### `ServerDNSTestAddresses hostname,hostname,...`

When we’re detecting DNS hijacking, make sure that these valid addresses aren’t getting redirected. If they are, then our DNS is completely useless, and we’ll reset our exit policy to "`reject`` `*`:`*". This option only affects name lookups that your server does on behalf of clients. (Default: `"`[`www.google.com`](https://docs.anyone.io/sdk/native-sdk/www.google.com)`,` [`www.mit.edu`](https://docs.anyone.io/sdk/native-sdk/www.mit.edu)`,` [`www.yahoo.com`](https://docs.anyone.io/sdk/native-sdk/www.yahoo.com)`,` [`www.slashdot.org`](https://docs.anyone.io/sdk/native-sdk/www.slashdot.org)`"`)

#### `ServerTransportListenAddr transport IP:PORT`

When this option is set, Anon will suggest `IP:PORT` as the listening address of any pluggable transport proxy that tries to launch transport. (IPv4 addresses should written as-is; IPv6 addresses should be wrapped in square brackets.) (Default: `none`)

#### `ServerTransportOptions transport k=v k=v ...`

When this option is set, Anon will pass the k=v parameters to any pluggable transport proxy that tries to launch transport.

(Example: `ServerTransportOptions obfs45 shared-secret=bridgepasswd cache=/var/lib/anon/cache`) (Default: `none`)

#### `ServerTransportPlugin transport exec path-to-binary [options]`

The Anon relay launches the pluggable transport proxy in path-to-binary using options as its command-line options, and expects to receive proxied client traffic from it. (Default: `none`)

#### `ShutdownWaitLength NUM`

When we get a SIGINT and we’re a server, we begin shutting down: we close listeners and start refusing new circuits. After `NUM` seconds, we exit. If we get a second SIGINT, we exit immediately. (Default: `30 seconds`)

#### `SigningKeyLifetime N days|weeks|months`

"For how long should each **Ed25519** signing key be valid?" Anon uses a permanent master identity key that can be kept offline, and periodically generates new "**signing**" keys that it uses online. This option configures their lifetime. (Default: `30 days`)

#### `SSLKeyLifetime N minutes|hours|days|weeks`

When creating a link certificate for our outermost SSL handshake, set its lifetime to this amount of time. If set to `0`, Anon will choose some reasonable random defaults. (Default: `0`)

#### `BridgeRecordUsageByCountry 0|1`

When this option is enabled and [`BridgeRelay`](#bridgerelay-0-or-1) is also enabled, and we have GeoIP data, Anon keeps a per-country count of how many client addresses have contacted it so that it can help the bridge authority guess which countries have blocked access to it. If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it will be published as part of the extra-info document. (Default: `1`)

#### `CellStatistics 0|1`

**Relays only**. When this option is enabled, Anon collects statistics about cell processing (i.e. mean time a cell is spending in a queue, mean number of cells in a queue and mean number of processed cells per circuit) and writes them into disk every 24 hours. Onion router operators may use the statistics for performance monitoring. If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it will published as part of the extra-info document. (Default: `0`)

#### `ConnDirectionStatistics 0|1`

**Relays only**. When this option is enabled, Anon writes statistics on the amounts of traffic it passes between itself and other relays to disk every 24 hours. Enables relay operators to monitor how much their relay is being used as middle node in the circuit. If `ExtraInfoStatistics` is enabled, it will be published as part of the extra-info document. (Default: `0`)

#### `DirReqStatistics 0|1`

**Relays and bridges only**. When this option is enabled, a Anon directory writes statistics on the number and response time of network status requests to disk every 24 hours. Enables relay and bridge operators to monitor how much their server is being used by clients to learn about Anon network. If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it will published as part of the extra-info document. (Default: `1`)

#### `EntryStatistics 0|1`

**Relays only**. When this option is enabled, Anon writes statistics on the number of directly connecting clients to disk every 24 hours. Enables relay operators to monitor how much inbound traffic that originates from Anon clients passes through their server to go further down the Anon network. If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it will be published as part of the extra-info document. (Default: `0`)

#### `ExitPortStatistics 0|1`

**Exit relays only**. When this option is enabled, Anon writes statistics on the number of relayed bytes and opened stream per exit port to disk every 24 hours. Enables exit relay operators to measure and monitor amounts of traffic that leaves Anon network through their exit node. If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it will be published as part of the extra-info document. (Default: `0`)

#### `ExtraInfoStatistics 0|1`

When this option is enabled, Anon includes previously gathered statistics in its extra-info documents that it uploads to the directory authorities. Disabling this option also removes bandwidth usage statistics, and GeoIPFile and GeoIPv6File hashes from the extra-info file. [`Bridge`](#bridge-transport-ip-orport-fingerprint) [`ServerTransportPlugin`](#servertransportplugin-transport-exec-path-to-binary-options) lines are always included in the extra-info file, because they are required by BridgeDB. (Default: `1`)

#### `HiddenServiceStatistics 0|1`

**Relays and bridges only**. When this option is enabled, a Anon relay writes obfuscated statistics on its role as hidden-service directory, introduction point, or rendezvous point to disk every 24 hours. If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it will be published as part of the extra-info document. (Default: `1`)

#### `OverloadStatistics 0|1*`

**Relays and bridges only**. When this option is enabled, a Anon relay will write an overload general line in the server descriptor if the relay is considered overloaded. (Default: `1`)

A relay is considered overloaded if at least one of these conditions is met:

• Onionskins are starting to be dropped.

• The **OOM** was invoked.

• (**Exit only**) DNS timeout occurs X% of the time over Y seconds (values controlled by consensus parameters, see `param-spec.txt`).

If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it can also put two more specific overload lines in the **extra-info** document if at least one of these conditions is met:

• TCP Port exhaustion.

• Connection rate limits have been reached (read and write side).

#### `PaddingStatistics 0|1`

**Relays and bridges only**. When this option is enabled, Anon collects statistics for padding cells sent and received by this relay, in addition to total cell counts. These statistics are rounded, and omitted if traffic is low. This information is important for load balancing decisions related to padding. If [`ExtraInfoStatistics`](#extrainfostatistics-0-or-1) is enabled, it will be published as a part of the extra-info document. (Default: `1`)

***

### CLIENT OPTIONS

The following options are useful only for clients (that is, if [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags), [`HTTPTunnelPort`](#httptunnelport-address-port-or-auto-isolation-flags), [`TransPort`](#transport-address-port-or-auto-isolation-flags), [`DNSPort`](#dnsport-address-port-or-auto-isolation-flags), or [`NATDPort`](#natdport-address-port-or-auto-isolation-flags) is **non-zero**):

#### `AllowNonRFC953Hostnames 0|1`

When this option is disabled, Anon blocks hostnames containing illegal characters (like `@` and `:`) rather than sending them to an exit node to be resolved. This helps trap accidental attempts to resolve URLs and so on. (Default: `0`)

#### `AutomapHostsOnResolve 0|1`

When this option is enabled, and we get a request to resolve an address that ends with one of the suffixes in [`AutomapHostsSuffixes`](#automaphostssuffixes-suffix-suffix), we map an unused virtual address to that address, and return the new virtual address. This is handy for making "**.onion**" addresses work with applications that resolve an address and then connect to it. (Default: `0`)

#### `AutomapHostsSuffixes SUFFIX,SUFFIX,...`

A comma-separated list of suffixes to use with [`AutomapHostsOnResolve`](#automaphostsonresolve-0-or-1). The "`.`" suffix is equivalent to "all addresses." (Default: `.exit,.onion`).

#### `Bridge [transport] IP:ORPort [fingerprint]`

When set along with [`UseBridges`](#usebridges-0-or-1), instructs Anon to use the relay at "`IP:ORPort`" as a "**bridge**" relaying into the Anon network. If "`fingerprint`" is provided (using the same format as for [`DirAuthority`](#dirauthority-nickname-flags-ipv4address-dirport-fingerprint)), we will verify that the relay running at that location has the right fingerprint. We also use fingerprint to look up the bridge descriptor at the bridge authority, if it’s provided and if [`UpdateBridgesFromAuthority`](#updatebridgesfromauthority-0-or-1) is set too.

If "`transport`" is provided, it must match a [`ClientTransportPlugin`](#clienttransportplugin-transport-socks4-or-socks5-ip-port) line. We then use that pluggable transport’s proxy to transfer data to the bridge, rather than connecting to the bridge directly. Some transports use a transport-specific method to work out the remote address to connect to. These transports typically ignore the "`IP:ORPort`" specified in the bridge line.

Anon passes any "`key=val`" settings to the pluggable transport proxy as per-connection arguments when connecting to the bridge. Consult the documentation of the pluggable transport for details of what arguments it supports.

#### `CircuitPadding 0|1`

If set to `0`, Anon will not pad client circuits with additional cover traffic. Only clients may set this option. This option should be offered via the UI to mobile users for use where bandwidth may be expensive. If set to `1`, padding will be negotiated as per the consensus and relay support (unlike [`ConnectionPadding`](#connectionpadding-0-or-1-or-auto), `CircuitPadding` cannot be force-enabled). (Default: `1`)

#### `ReducedCircuitPadding 0|1`

If set to `1`, Anon will only use circuit padding algorithms that have low overhead. Only clients may set this option. This option should be offered via the UI to mobile users for use where bandwidth may be expensive. (Default: `0`)

#### `ClientBootstrapConsensusAuthorityDownloadInitialDelay N`

Initial delay in seconds for when clients should download consensuses from authorities if they are bootstrapping (that is, they don’t have a usable, reasonably live consensus). Only used by clients fetching from a list of fallback directory mirrors. This schedule is advanced by (potentially concurrent) connection attempts, unlike other schedules, which are advanced by connection failures. (Default: `6`)

#### `ClientBootstrapConsensusAuthorityOnlyDownloadInitialDelay N`

Initial delay in seconds for when clients should download consensuses from authorities if they are bootstrapping (that is, they don’t have a usable, reasonably live consensus). Only used by clients which don’t have or won’t fetch from a list of fallback directory mirrors. This schedule is advanced by (potentially concurrent) connection attempts, unlike other schedules, which are advanced by connection failures. (Default: `0`)

#### `ClientBootstrapConsensusFallbackDownloadInitialDelay N`

Initial delay in seconds for when clients should download consensuses from fallback directory mirrors if they are bootstrapping (that is, they don’t have a usable, reasonably live consensus). Only used by clients fetching from a list of fallback directory mirrors. This schedule is advanced by (potentially concurrent) connection attempts, unlike other schedules, which are advanced by connection failures. (Default: `0`)

#### `ClientBootstrapConsensusMaxInProgressTries NUM`

Try this many simultaneous connections to download a consensus before waiting for one to complete, timeout, or error out. (Default: `3`)

#### `ClientDNSRejectInternalAddresses 0|1`

If true, Anon does not believe any anonymously retrieved DNS answer that tells it that an address resolves to an internal address (like `127.0.0.1` or `192.168.0.1`). This option prevents certain browser-based attacks; it is not allowed to be set on the default network. (Default: `1`)

#### `ClientOnionAuthDir path`

Path to the directory containing v3 hidden service authorization files. Each file is for a single onion address, and the files **MUST** have the suffix "`.auth_private`" (i.e. "`bob_onion.auth_private`"). The content format **MUST** be:

`:descriptor:x25519:`

It **MUST NOT** have the "`.onion`" suffix. It is the **base32** representation of the raw key bytes only (**32 bytes** for **x25519**).

#### `ClientOnly 0|1`

If set to `1`, Anon will not run as a relay or serve directory requests, even if the [`ORPort`](#orport-address-port-or-auto-flags), [`ExtORPort`](#extorport-address-port-or-auto), or [`DirPort`](#dirport-address-port-or-auto-flags) options are set. (This config option is mostly unnecessary: it was added back when considering having clients auto-promote themselves to being relays if they were stable and fast enough. The current behavior is simply that Anon is a client unless [`ORPort`](#orport-address-port-or-auto-flags), [`ExtORPort`](#extorport-address-port-or-auto), or [`DirPort`](#dirport-address-port-or-auto-flags) are configured.) (Default: `0`)

#### `ClientPreferIPv6ORPort 0|1|auto`

If this option is set to `1`, Anon prefers an OR port with an IPv6 address over one with IPv4 if a given entry node has both. (Anon also prefers an IPv6 ORPort if IPv4Client is set to `0`.) If this option is set to `auto`, Anon bridge clients prefer the configured bridge address, and other clients prefer IPv4. Other things may influence the choice. This option breaks a tie to the favor of IPv6. (Default: `auto`)

#### `ClientRejectInternalAddresses 0|1`

If true, Anon does not try to fulfill requests to connect to an internal address (like `127.0.0.1` or `192.168.0.1`) unless an exit node is specifically requested (for example, via a .exit hostname, or a controller request). If true, multicast DNS hostnames for machines on the local network (of the form `*.local`) are also rejected. (Default: `1`)

#### `ClientUseIPv4 0|1`

If this option is set to `0`, Anon will avoid connecting to directory servers and entry nodes over IPv4. Note that clients with an IPv4 address in a **Bridge**, **proxy**, or **pluggable transport line** will try connecting over IPv4 even if [`ClientUseIPv4`](#clientuseipv4-0-or-1) is set to `0`. (Default: `1`)

#### `ClientUseIPv6 0|1`

If this option is set to `1`, Anon might connect to directory servers or entry nodes over IPv6. For IPv6 only hosts, you need to also set [`ClientUseIPv4`](#clientuseipv4-0-or-1) to `0` to disable IPv4. Note that clients configured with an IPv6 address in a Bridge, proxy, or pluggable transport line will try connecting over IPv6 even if [`ClientUseIPv6`](#clientuseipv6-0-or-1) is set to `0`. (Default: `1`)

#### `ConnectionPadding 0|1|auto`

This option governs Anon’s use of padding to defend against some forms of traffic analysis. If it is set to `auto`, Anon will send padding only if both the client and the relay support it. If it is set to `0`, Anon will not send any padding cells. If it is set to `1`, Anon will still send padding for client connections regardless of relay support. Only clients may set this option. This option should be offered via the UI to mobile users for use where bandwidth may be expensive. (Default: `auto`)

#### `ReducedConnectionPadding 0|1`

If set to `1`, Anon will not not hold OR connections open for very long, and will send less padding on these connections. Only clients may set this option. This option should be offered via the UI to mobile users for use where bandwidth may be expensive. (Default: `0`)

#### `DNSPort [address:]port|auto [isolation flags]`

If non-zero, open this port to listen for UDP DNS requests, and resolve them anonymously. This port only handles A, AAAA, and PTR requests---it doesn’t handle arbitrary DNS request types. Set the port to "`auto`" to have Anon pick a port for you. This directive can be specified multiple times to bind to multiple addresses/ports. See [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) for an explanation of isolation flags. (Default: `0`)

#### `DownloadExtraInfo 0|1`

If true, Anon downloads and caches "**extra-info**" documents. These documents contain information about servers other than the information in their regular server descriptors. Anon does not use this information for anything itself; to save bandwidth, leave this option turned off. (Default: `0`)

#### `EnforceDistinctSubnets 0|1`

If `1`, Anon will not put two servers whose IP addresses are "**too close**" on the same circuit. Currently, two addresses are "**too close**" if they lie in the same **/16** range. (Default: `1`)

#### `FascistFirewall 0|1`

If `1`, Anon will only create outgoing connections to ORs running on ports that your firewall allows (defaults to `80` and `443`; see [`FirewallPorts`](#firewallports-ports)). This will allow you to run Anon as a client behind a firewall with restrictive policies, but will not allow you to run as a server behind such a firewall. If you prefer more fine-grained control, use [`ReachableAddresses`](#reachableaddresses-ip-mask-port) instead.

#### `HTTPTunnelPort [address:]port|auto [isolation flags]`

Open this port to listen for proxy connections using the "**HTTP CONNECT**" protocol instead of **SOCKS**. Set this to `0` if you don’t want to allow "**HTTP CONNECT**" connections. Set the port to "`auto`" to have Anon pick a port for you. This directive can be specified multiple times to bind to multiple addresses/ports. If multiple entries of this option are present in your configuration file, Anon will perform stream isolation between listeners by default. See [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) for an explanation of isolation flags. (Default: `0`)

#### `LongLivedPorts PORTS`

A list of ports for services that tend to have long-running connections (e.g. chat and interactive shells). Circuits for streams that use these ports will contain only high-uptime nodes, to reduce the chance that a node will go down before the stream is finished. Note that the list is also honored for circuits (both client and service side) involving hidden services whose virtual port is in this list. (Default: `21, 22, 706, 1863, 5050, 5190, 5222, 5223, 6523, 6667, 6697, 8300`)

#### `MapAddress address newaddress`

When a request for address arrives to Anon, it will transform to **newaddress** before processing it. For example, if you always want connections to **[www.example.com](http://www.example.com)** to exit via **anonserver** (where **anonserver** is the fingerprint of the server), use "`MapAddress www.example.com www.example.com.anonserver.exit`". If the value is prefixed with a "`*.`", matches an entire domain. For example, if you always want connections to **example.com** and any of its subdomains to exit via **anonserver** (where **anonserver** is the fingerprint of the server), use "`MapAddress *.example.com`` `*`.example.com.anonserver.exit`". (Note the leading "*`.`" in each part of the directive.) You can also redirect all subdomains of a domain to a single address. For example, "`MapAddress *.example.com www.example.com`". If the specified exit is not available, or the exit can not connect to the site, Anon will fail any connections to the mapped address.

#### `MaxCircuitDirtiness NUM`

Feel free to reuse a circuit that was first used at most `NUM` seconds ago, but never attach a new stream to a circuit that is too old. For hidden services, this applies to the last time a circuit was used, not the first. Circuits with streams constructed with `SOCKS` authentication via [`SocksPorts`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) that have [`KeepAliveIsolateSOCKSAuth`](#keepaliveisolatesocksauth) also remain alive for [`MaxCircuitDirtiness`](#maxcircuitdirtiness-num) seconds after carrying the last such stream. (Default: `10 minutes`)

#### `MaxClientCircuitsPending NUM`

Do not allow more than `NUM` circuits to be pending at a time for handling client streams. A circuit is pending if we have begun constructing it, but it has not yet been completely constructed. (Default: `32`)

#### `NATDPort [address:]port|auto [isolation flags]`

Open this port to listen for connections from old versions of **ipfw** (as included in old versions of FreeBSD, etcetera) using the **NATD** protocol. Use `0` if you don’t want to allow **NATD** connections. Set the port to "`auto`" to have Anon pick a port for you. This directive can be specified multiple times to bind to multiple addresses/ports. If multiple entries of this option are present in your configuration file, Anon will perform stream isolation between listeners by default. See [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) for an explanation of isolation flags.

This option is only for people who cannot use [`TransPort`](#transport-address-port-or-auto-isolation-flags). (Default: `0`)

#### `NewCircuitPeriod NUM`

Every `NUM` seconds consider whether to build a new circuit. (Default: `30 seconds`)

#### `PathBiasCircThreshold NUM`

#### `PathBiasDropGuards NUM`

#### `PathBiasExtremeRate NUM`

#### `PathBiasNoticeRate NUM`

#### `PathBiasWarnRate NUM`

#### `PathBiasScaleThreshold NUM`

These options override the default behavior of Anon’s (currently experimental) path bias detection algorithm. To try to find broken or misbehaving guard nodes, Anon looks for nodes where more than a certain fraction of circuits through that guard fail to get built.

The [`PathBiasCircThreshold`](#pathbiascircthreshold-num) option controls how many circuits we need to build through a guard before we make these checks. The [`PathBiasNoticeRate`](#pathbiasnoticerate-num), [`PathBiasWarnRate`](#pathbiaswarnrate-num) and [`PathBiasExtremeRate`](#pathbiasextremerate-num) options control what fraction of circuits must succeed through a guard so we won’t write log messages. If less than [`PathBiasExtremeRate`](#pathbiasextremerate-num) circuits succeed and [`PathBiasDropGuards`](#pathbiasdropguards-num) is set to `1`, we disable use of that guard.

When we have seen more than [`PathBiasScaleThreshold`](#pathbiasscalethreshold-num) circuits through a guard, we scale our observations by `0.5` (governed by the consensus) so that new observations don’t get swamped by old ones.

By default, or if a negative value is provided for one of these options, Anon uses reasonable defaults from the **networkstatus** consensus document. If no defaults are available there, these options default to `150`, `.70`, `.50`, `.30`, `0`, and `300` respectively.

#### `PathBiasUseThreshold NUM`

#### `PathBiasNoticeUseRate NUM`

#### `PathBiasExtremeUseRate NUM`

#### `PathBiasScaleUseThreshold NUM`

Similar to the above options, these options override the default behavior of Anon’s (currently experimental) path use bias detection algorithm.

Where as the path bias parameters govern thresholds for successfully building circuits, these four path use bias parameters govern thresholds only for circuit usage. Circuits which receive no stream usage are not counted by this detection algorithm. A used circuit is considered successful if it is capable of carrying streams or otherwise receiving well-formed responses to `RELAY` cells.

By default, or if a negative value is provided for one of these options, Anon uses reasonable defaults from the **networkstatus** consensus document. If no defaults are available there, these options default to `20`, `.80`, `.60`, and `100`, respectively.

#### `PathsNeededToBuildCircuits NUM`

Anon clients don’t build circuits for user traffic until they know about enough of the network so that they could potentially construct enough of the possible paths through the network. If this option is set to a fraction between `0.25` and `0.95`, Anon won’t build circuits until it has enough descriptors or **microdescriptors** to construct that fraction of possible paths. Note that setting this option too low can make your Anon client less anonymous, and setting it too high can prevent your Anon client from bootstrapping. If this option is negative, Anon will use a default value chosen by the directory authorities. If the directory authorities do not choose a value, Anon will default to `0.6`. (Default: `-1`)

#### `ReachableAddresses IP[/MASK][:PORT]...`

A comma-separated list of IP addresses and ports that your firewall allows you to connect to. The format is as for the addresses in [`ExitPolicy`](#exitpolicy-policy-policy), except that "`accept`" is understood unless "`reject`" is explicitly provided. For example, '`ReachableAddresses 99.0.0.0/8, reject 18.0.0.0/8:80, accept *:80`' means that your firewall allows connections to everything inside net `99`, rejects port `80` connections to net `18`, and accepts connections to port `80` otherwise. (Default: `'accept`` `*`:`*`'`.)

#### `ReachableORAddresses IP[/MASK][:PORT]...`

Like [`ReachableAddresses`](#reachableaddresses-ip-mask-port), a list of addresses and ports. Anon will obey these restrictions when connecting to Onion Routers, using **TLS/SSL**. If not set explicitly then the value of [`ReachableAddresses`](#reachableaddresses-ip-mask-port) is used. If [`HTTPSProxy`](#httpsproxy-host-port) is set then these connections will go through that proxy.

The separation between [`ReachableORAddresses`](#reachableoraddresses-ip-mask-port) and ~~`ReachableDirAddresses`~~ is only interesting when you are connecting through proxies (see [`HTTPSProxy`](#httpsproxy-host-port)). Most proxies limit TLS connections (which Anon uses to connect to Onion Routers) to port `443`, and some limit HTTP GET requests (which Anon uses for fetching directory information) to port `80`.

#### `SafeSocks 0|1`

When this option is enabled, Anon will reject application connections that use unsafe variants of the socks protocol — ones that only provide an IP address, meaning the application is doing a DNS resolve first. Specifically, these are socks4 and socks5 when not doing remote DNS. (Default: `0`)

#### `TestSocks 0|1`

When this option is enabled, Anon will make a notice-level log entry for each connection to the Socks port indicating whether the request used a safe socks protocol or an unsafe one (see [`SafeSocks`](#safesocks-0-or-1)). This helps to determine whether an application using Anon is possibly leaking DNS requests. (Default: `0`)

#### `WarnPlaintextPorts port,port,...`

Tells Anon to issue a warnings whenever the user tries to make an anonymous connection to one of these ports. This option is designed to alert users to services that risk sending passwords in the clear. (Default: `23,109,110,143`)

#### `RejectPlaintextPorts port,port,...`

Like [`WarnPlaintextPorts`](#warnplaintextports-port-port), but instead of warning about risky port uses, Anon will instead refuse to make the connection. (Default: `None`)

#### `SocksPolicy policy,policy,...`

Set an entrance policy for this server, to limit who can connect to the [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) and [`DNSPort`](#dnsport-address-port-or-auto-isolation-flags) ports. The policies have the same form as exit policies below, except that port specifiers are ignored. Any address not matched by some entry in the policy is accepted.

#### `SocksPort [address:]port|unix:path|auto [flags] [isolation flags]`

Open this port to listen for connections from **SOCKS**-speaking applications. Set this to `0` if you don’t want to allow application connections via **SOCKS**. Set it to "`auto`" to have Anon pick a port for you. This directive can be specified multiple times to bind to multiple addresses/ports. If a unix domain socket is used, you may quote the path using standard C escape sequences. Most flags are off by default, except where specified. Flags that are on by default can be disabled by putting "`No`" before the flag name. (Default: `9050`)

{% hint style="warning" %}
Although this option allows you to specify an IP address other than localhost, you should do so only with extreme caution. The **SOCKS** protocol is unencrypted and (as we use it) unauthenticated, so exposing it in this way could leak your information to anybody watching your network, and allow anybody to use your computer as an open proxy.
{% endhint %}

If multiple entries of this option are present in your configuration file, Anon will perform stream isolation between listeners by default. The isolation flags arguments give Anon rules for which streams received on this SocksPort are allowed to share circuits with one another. Recognized isolation flags are:

#### `IsolateClientAddr`

Don’t share circuits with streams from a different client address. (On by default and strongly recommended when supported; you can disable it with [`IsolateClientAddr`](#isolateclientaddr). Unsupported and force-disabled when using Unix domain sockets.)

#### `IsolateSOCKSAuth`

Don’t share circuits with streams for which different SOCKS authentication was provided. (For [`HTTPTunnelPort`](#httptunnelport-address-port-or-auto-isolation-flags) connections, this option looks at the Proxy-Authorization and X-Anon-Stream-Isolation headers. On by default; you can disable it with [`IsolateSOCKSAuth`](#isolatesocksauth).)

#### `IsolateClientProtocol`

Don’t share circuits with streams using a different protocol. (**SOCKS 4**, **SOCKS 5**, [**HTTPTunnelPort**](#httptunnelport-address-port-or-auto-isolation-flags) connections, [`TransPort`](#transport-address-port-or-auto-isolation-flags) connections, [`NATDPort`](#natdport-address-port-or-auto-isolation-flags) connections, and [`DNSPort`](#dnsport-address-port-or-auto-isolation-flags) requests are all considered to be different protocols.)

#### `IsolateDestPort`

Don’t share circuits with streams targeting a different destination port.

#### `IsolateDestAddr`

Don’t share circuits with streams targeting a different destination address.

#### `KeepAliveIsolateSOCKSAuth`

If [`IsolateSOCKSAuth`](#isolatesocksauth) is enabled, keep alive circuits while they have at least one stream with **SOCKS** authentication active. After such a circuit is idle for more than [`MaxCircuitDirtiness`](#maxcircuitdirtiness-num) seconds, it can be closed.

#### `SessionGroup=INT`

If no other isolation rules would prevent it, allow streams on this port to share circuits with streams from every other port with the same session group. (By default, streams received on different [`SocksPorts`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags), [`TransPorts`](#transport-address-port-or-auto-isolation-flags), etc are always isolated from one another. This option overrides that behavior.)

Other recognized flags for a [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) are:

#### `NoIPv4Traffic`

Tell exits to not connect to IPv4 addresses in response to **SOCKS** requests on this connection.

#### `IPv6Traffic`

Tell exits to allow IPv6 addresses in response to **SOCKS** requests on this connection, so long as **SOCKS5** is in use. (**SOCKS4** can’t handle IPv6.)

#### `PreferIPv6`

Tells exits that, if a host has both an IPv4 and an IPv6 address, we would prefer to connect to it via IPv6. (IPv4 is the default.)

#### `NoDNSRequest`

Do not ask exits to resolve DNS addresses in **SOCKS5** requests. Anon will connect to IPv4 addresses, IPv6 addresses (if [`IPv6Traffic`](#ipv6traffic) is set) and .onion addresses.

#### `NoOnionTraffic`

Do not connect to .onion addresses in **SOCKS5** requests.

#### `CacheIPv4DNS`

Tells the client to remember IPv4 DNS answers we receive from exit nodes via this connection.

#### `CacheIPv6DNS`

Tells the client to remember IPv6 DNS answers we receive from exit nodes via this connection.

#### `GroupWritable`

Unix domain sockets only: makes the socket get created as group-writable.

#### `WorldWritable`

Unix domain sockets only: makes the socket get created as world-writable.

#### `CacheDNS`

Tells the client to remember all DNS answers we receive from exit nodes via this connection.

#### `UseIPv4Cache`

Tells the client to use any cached IPv4 DNS answers we have when making requests via this connection. (**NOTE**: This option, or [`UseIPv6Cache`](#useipv6cache) or [`UseDNSCache`](#usednscache), can harm your anonymity, and probably won’t help performance as much as you might expect. **Use with care!**)

#### `UseIPv6Cache`

Tells the client to use any cached IPv6 DNS answers we have when making requests via this connection.

#### `UseDNSCache`

Tells the client to use any cached DNS answers we have when making requests via this connection.

#### `NoPreferIPv6Automap`

When serving a hostname lookup request on this port that should get automapped (according to [`AutomapHostsOnResolve`](#automaphostsonresolve-0-or-1)), if we could return either an IPv4 or an IPv6 answer, prefer an IPv4 answer. (Anon prefers IPv6 by default.)

#### `PreferSOCKSNoAuth`

Ordinarily, when an application offers both "**username/password authentication**" and "**no authentication**" to Anon via **SOCKS5**, Anon selects username/password authentication so that [`IsolateSOCKSAuth`](#isolatesocksauth) can work. This can confuse some applications, if they offer a username/password combination then get confused when asked for one. You can disable this behavior, so that Anon will select "**No authentication**" when [`IsolateSOCKSAuth`](#isolatesocksauth) is disabled, or when this option is set.

#### `ExtendedErrors`

"Return extended error code in the **SOCKS** reply. So far, the possible errors are:

"X'F0' Onion Service Descriptor Can Not be Found"

"The requested onion service descriptor can't be found on the hashring and thus not reachable by the client. (v3 only)"

"X'F1' Onion Service Descriptor Is Invalid"

"The requested onion service descriptor can't be parsed or signature validation failed. (v3 only)"

"X'F2' Onion Service Introduction Failed"

"All introduction attempts failed either due to a combination of NACK by the intro point or time out. (v3 only)"

"X'F3' Onion Service Rendezvous Failed"

"Every rendezvous circuit has timed out and thus the client is unable to rendezvous with the service. (v3 only)"

"X'F4' Onion Service Missing Client Authorization"

"Client was able to download the requested onion service descriptor but is unable to decrypt its content because it is missing client authorization information. (v3 only)"

"X'F5' Onion Service Wrong Client Authorization"

"Client was able to download the requested onion service descriptor but is unable to decrypt its content using the client authorization information it has. This means the client access were revoked. (v3 only)"

"X'F6' Onion Service Invalid Address"

"The given .onion address is invalid. In one of these cases this error is returned: address checksum doesn't match, ed25519 public key is invalid or the encoding is invalid. (v3 only)"

"X'F7' Onion Service Introduction Timed Out"

"Similar to X'F2' code but in this case, all introduction attempts have failed due to a time out. (v3 only)"

"Flags are processed left to right. If flags conflict, the last flag on the line is used, and all earlier flags are ignored. No error is issued for conflicting flags."

#### `TokenBucketRefillInterval NUM [msec|second]`

Set the refill delay interval of Anon’s token bucket to `NUM` milliseconds. `NUM` must be between `1` and `1000`, inclusive. When Anon is out of bandwidth, on a connection or globally, it will wait up to this long before it tries to use that connection again. Note that bandwidth limits are still expressed in bytes per second: this option only affects the frequency with which Anon checks to see whether previously exhausted connections may read again. Can not be changed while Anon is running. (Default: `100 msec`)

#### `TrackHostExits host,.domain,...`

For each value in the comma separated list, Anon will track recent connections to hosts that match this value and attempt to reuse the same exit node for each. If the value is prepended with a '`.`', it is treated as matching an entire domain. If one of the values is just a '`.`', it means match everything. This option is useful if you frequently connect to sites that will expire all your authentication cookies (i.e. log you out) if your IP address changes. Note that this option does have the disadvantage of making it more clear that a given history is associated with a single user. However, most people who would wish to observe this will observe it through cookies or other protocol-specific means anyhow.

#### `TrackHostExitsExpire NUM`

Since exit servers go up and down, it is desirable to expire the association between host and exit server after `NUM` seconds. The default is `1800` seconds (**30 minutes**).

#### `TransPort [address:]port|auto [isolation flags]`

Open this port to listen for transparent proxy connections. Set this to `0` if you don’t want to allow transparent proxy connections. Set the port to "`auto`" to have Anon pick a port for you. This directive can be specified multiple times to bind to multiple addresses/ports. If multiple entries of this option are present in your configuration file, Anon will perform stream isolation between listeners by default. See [`SocksPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) for an explanation of isolation flags.

[`TransPort`](#transport-address-port-or-auto-isolation-flags) requires OS support for transparent proxies, such as BSDs' pf or Linux’s IPTables. If you’re planning to use Anon as a transparent proxy for a network, you’ll want to examine and change [`VirtualAddrNetwork`](#virtualaddrnetworkipv4-ipv4address-bits) from the default setting. (Default: `0`)

#### `TransProxyType default|TPROXY|ipfw|pf-divert`

`TransProxyType` may only be enabled when there is transparent proxy listener enabled.

Set this to "**TPROXY**" if you wish to be able to use the **TPROXY** Linux module to transparently proxy connections that are configured using the [`TransPort`](#transport-address-port-or-auto-isolation-flags) option. Detailed information on how to configure the **TPROXY** feature can be found in the Linux kernel source tree in the file `Documentation/networking/tproxy.txt.`

Set this option to "`ipfw`" to use the FreeBSD ipfw interface.

On \*BSD operating systems when using pf, set this to "`pf-divert`" to take advantage of divert-to rules, which do not modify the packets like rdr-to rules do. Detailed information on how to configure pf to use divert-to rules can be found in the **pf.conf(5)** manual page. On OpenBSD, divert-to is available to use on versions greater than or equal to OpenBSD 4.4.

Set this to "`default`", or leave it unconfigured, to use regular IPTables on Linux, or to use pf rdr-to rules on \*BSD systems.

(Default: "default")

#### `UpdateBridgesFromAuthority 0|1`

When set (along with [`UseBridges`](#usebridges-0-or-1)), Anon will try to fetch bridge descriptors from the configured bridge authorities when feasible. It will fall back to a direct request if the authority responds with a 404. (Default: `0`)

#### `UseBridges 0|1`

When set, Anon will fetch descriptors for each bridge listed in the "[`Bridge`](#bridge-transport-ip-orport-fingerprint)" config lines, and use these relays as both entry guards and directory guards. (Default: `0`)

#### `UseEntryGuards 0|1`

If this option is set to `1`, we pick a few long-term entry servers, and try to stick with them. This is desirable because constantly changing servers increases the odds that an adversary who owns some servers will observe a fraction of your paths. Entry Guards can not be used by Directory Authorities or Single Onion Services. In these cases, this option is ignored. (Default: `1`)

#### `UseGuardFraction 0|1|auto`

This option specifies whether clients should use the **guardfraction** information found in the consensus during path selection. If it’s set to auto, clients will do what the `UseGuardFraction` consensus parameter tells them to do. (Default: `auto`)

#### `GuardLifetime N days|weeks|months`

If [`UseEntryGuards`](#useentryguards-0-or-1) is set, minimum time to keep a guard on our guard list before picking a new one. If less than one day, we use defaults from the consensus directory. (Default: `0`)

#### `NumDirectoryGuards NUM`

If [`UseEntryGuards`](#useentryguards-0-or-1) is set to 1, we try to make sure we have at least `NUM` routers to use as directory guards. If this option is set to `0`, use the value from the **guard-n-primary-dir-guards-to-use** consensus parameter, and default to `3` if the consensus parameter isn’t set. (Default: `0`)

#### `NumEntryGuards NUM`

If [`UseEntryGuards`](#useentryguards-0-or-1) is set to `1`, we will try to pick a total of `NUM` routers as long-term entries for our circuits. If `NUM` is `0`, we try to learn the number from the **guard-n-primary-guards-to-use** consensus parameter, and default to `1` if the consensus parameter isn’t set. (Default: `0`)

#### `NumPrimaryGuards NUM`

If [`UseEntryGuards`](#useentryguards-0-or-1) is set to `1`, we will try to pick `NUM` routers for our primary guard list, which is the set of routers we strongly prefer when connecting to the Anon network. If `NUM` is `0`, we try to learn the number from the guard-n-primary-guards consensus parameter, and default to `3` if the consensus parameter isn’t set. (Default: `0`)

#### `VanguardsLiteEnabled 0|1|auto`

This option specifies whether clients should use the **vanguards-lite** subsystem to protect against guard discovery attacks. If it’s set to `auto`, clients will do what the **vanguards-lite-enabled** consensus parameter tells them to do, and will default to enable the subsystem if the consensus parameter isn’t set. (Default: `auto`)

#### `UseMicrodescriptors 0|1|auto`

**Microdescriptors** are a smaller version of the information that Anon needs in order to build its circuits. Using **microdescriptors** makes Anon clients download less directory information, thus saving bandwidth. Directory caches need to fetch regular descriptors and **microdescriptors**, so this option doesn’t save any bandwidth for them. For legacy reasons, auto is accepted, but it has the same effect as 1. (Default: `auto`)

#### `VirtualAddrNetworkIPv4 IPv4Address/bits`

#### `VirtualAddrNetworkIPv6 [IPv6Address]/bits`

When Anon needs to assign a virtual (unused) address because of a `MAPADDRESS` command from the controller or the [`AutomapHostsOnResolve`](#automaphostsonresolve-0-or-1) feature, Anon picks an unassigned address from this range. (Defaults: `127.192.0.0/10` and `[FE80::]/10` respectively.)

When providing proxy server service to a network of computers using a tool like **dns-proxy-anon**, change the IPv4 network to "`10.192.0.0/10`" or "`172.16.0.0/12`" and change the IPv6 network to "`[FC00::]/7`". The default `VirtualAddrNetwork` address ranges on a properly configured machine will route to the loopback or link-local interface. The maximum number of bits for the network prefix is set to `104` for IPv6 and `16` for IPv4. However, a larger network (that is, one with a smaller prefix length) is preferable, since it reduces the chances for an attacker to guess the used IP. For local use, no change to the default `VirtualAddrNetwork` setting is needed.

#### **`DNSMappingFileMaxSize N B|KB|MB`**

The maximum size allowed for the `anyone_hosts` DNS mapping file in the data directory. If the file exceeds this size, it is rejected. Set this option to 0 to disable the size limit. (Default: `10 MB`)

***

### CIRCUIT TIMEOUT OPTIONS

The following options are useful for configuring timeouts related to building Anon circuits and using them:

#### `CircuitsAvailableTimeout NUM`

Anon will attempt to keep at least one open, unused circuit available for this amount of time. This option governs how long idle circuits are kept open, as well as the amount of time Anon will keep a circuit open to each of the recently used ports. This way when the Anon client is entirely idle, it can expire all of its circuits, and then expire its TLS connections. Note that the actual timeout value is uniformly randomized from the specified value to twice that amount. (Default: `30 minutes`; Max: `24 hours`)

#### `LearnCircuitBuildTimeout 0|1`

If `0`, [`CircuitBuildTimeout`](#circuitbuildtimeout-num) adaptive learning is disabled. (Default: `1`)

#### `CircuitBuildTimeout NUM`

Try for at most `NUM` seconds when building circuits. If the circuit isn’t open in that time, give up on it. If [`LearnCircuitBuildTimeout`](#learncircuitbuildtimeout-0-or-1) is `1`, this value serves as the initial value to use before a timeout is learned. If [`LearnCircuitBuildTimeout`](#learncircuitbuildtimeout-0-or-1) is `0`, this value is the only value used. (Default: `60 seconds`)

#### `CircuitStreamTimeout NUM`

If non-zero, this option overrides our internal timeout schedule for how many seconds until we detach a stream from a circuit and try a new circuit. If your network is particularly slow, you might want to set this to a number like `60`. (Default: `0`)

#### `SocksTimeout NUM`

Let a socks connection wait `NUM` seconds handshaking, and `NUM` seconds unattached waiting for an appropriate circuit, before we fail it. (Default: `2 minutes`)

### DORMANT MODE OPTIONS

Anon can enter dormant mode to conserve power and network bandwidth. The following options control when Anon enters and leaves dormant mode:

#### `DormantCanceledByStartup 0|1`

By default, Anon starts in **active** mode if it was **active** the last time it was shut down, and in **dormant** mode if it was **dormant**. But if this option is true, Anon treats every startup event as user activity, and Anon will never start in **Dormant** mode, even if it has been unused for a long time on previous runs. (Default: `0`)

{% hint style="warning" %}
Packagers and application developers should change the value of this option only with great caution: it has the potential to create spurious traffic on the network. This option should only be used if Anon is started by an affirmative user activity (like clicking on an application or running a command), and not if Anon is launched for some other reason (for example, by a startup process, or by an application that launches itself on every login.)
{% endhint %}

#### `DormantClientTimeout N minutes|hours|days|weeks`

If Anon spends this much time without any client activity, enter a **dormant** state where automatic circuits are not built, and directory information is not fetched. Does not affect servers or onion services. Must be at least `10 minutes`. (Default: `24 hours`)

#### `DormantOnFirstStartup 0|1`

If true, then the first time Anon starts up with a fresh [`DataDirectory`](#datadirectory-dir), it starts in **dormant** mode, and takes no actions until the user has made a request. (This mode is recommended if installing a Anon client for a user who might not actually use it.) If false, Anon bootstraps the first time it is started, whether it sees a user request or not.

After the first time Anon starts, it begins in **dormant** mode if it was **dormant** before, and not otherwise. (Default: `0`)

#### `DormantTimeoutDisabledByIdleStreams 0|1`

If true, then any open client stream (even one not reading or writing) counts as client activity for the purpose of [`DormantClientTimeout`](#dormantclienttimeout-n-minutes-or-hours-or-days-or-weeks). If false, then only network activity counts. (Default: `1`)

#### `DormantTimeoutEnabled 0|1`

If false, then no amount of time without activity is sufficient to make Anon go dormant. Setting this option to `0` is only recommended for special-purpose applications that need to use the Anon binary for something other than sending or receiving Anon traffic. (Default: `1`)

### NODE SELECTION OPTIONS

The following options restrict the nodes that a Anon client (or onion service) can use while building a circuit. These options can weaken your anonymity by making your client behavior different from other Anon clients:

#### `EntryNodes node,node,...`

A list of identity fingerprints and country codes of nodes to use for the first hop in your normal circuits. Normal circuits include all circuits except for direct connections to directory servers. The [`Bridge`](#bridge-transport-ip-orport-fingerprint) option overrides this option; if you have configured bridges and [`UseBridges`](#usebridges-0-or-1) is `1`, the Bridges are used as your entry nodes.

This option can appear multiple times: the values from multiple lines are spliced together.

The [`ExcludeNodes`](#excludenodes-node-node) option overrides this option: any node listed in both [`EntryNodes`](#entrynodes-node-node) and [`ExcludeNodes`](#excludenodes-node-node) is treated as excluded. See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes.

#### `ExcludeNodes node,node,...`

A list of identity fingerprints, country codes, and address patterns of nodes to avoid when building a circuit. Country codes are 2-letter **ISO3166** codes, and must be wrapped in braces; fingerprints may be preceded by a dollar sign. (Example: `ExcludeNodes ABCD1234CDEF5678ABCD1234CDEF5678ABCD1234, {cc}, 255.254.0.0/8`)

{% hint style="info" %}
This option can appear multiple times: the values from multiple lines are spliced together.
{% endhint %}

By default, this option is treated as a preference that Anon is allowed to override in order to keep working. For example, if you try to connect to a hidden service, but you have excluded all of the hidden service’s introduction points, Anon will connect to one of them anyway. If you do not want this behavior, set the [`StrictNodes`](#strictnodes-0-or-1) option (documented below).

Note also that if you are a relay, this (and the other node selection options below) only affects your own circuits that Anon builds for you. Clients can still build circuits through you to any node. Controllers can tell Anon to build circuits through any node.

Country codes are case-insensitive. The code "`{??}`" refers to nodes whose country can’t be identified. No country code, including `{??}`, works if no **GeoIPFile** can be loaded. See also the [`GeoIPExcludeUnknown`](#geoipexcludeunknown-0-or-1-or-auto) option below.

#### `ExcludeExitNodes node,node,...`

A list of identity fingerprints, country codes, and address patterns of nodes to never use when picking an exit node---that is, a node that delivers traffic for you outside the Anon network. Note that any node listed in [`ExcludeNodes`](#excludenodes-node-node) is automatically considered to be part of this list too. See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes. See also the caveats on the [`ExitNodes`](#exitnodes-node-node) option below.

{% hint style="info" %}
This option can appear multiple times: the values from multiple lines are spliced together.
{% endhint %}

#### `ExitNodes node,node,...`

A list of identity fingerprints, country codes, and address patterns of nodes to use as exit node---that is, a node that delivers traffic for you outside the Anon network. See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes.

{% hint style="info" %}
This option can appear multiple times: the values from multiple lines are spliced together.
{% endhint %}

Note that if you list too few nodes here, or if you exclude too many exit nodes with [`ExcludeExitNodes`](#excludeexitnodes-node-node), you can degrade functionality. For example, if none of the exits you list allows traffic on port `80` or `443`, you won’t be able to browse the web.

Note also that not every circuit is used to deliver traffic outside of the Anon network. It is normal to see non-exit circuits (such as those used to connect to hidden services, those that do directory fetches, those used for relay reachability self-tests, and so on) that end at a non-exit node. To keep a node from being used entirely, see [`ExcludeNodes`](#excludenodes-node-node) and [`StrictNodes`](#strictnodes-0-or-1).

The [`ExcludeNodes`](#excludenodes-node-node) option overrides this option: any node listed in both `ExitNodes` and [`ExcludeNodes`](#excludenodes-node-node) is treated as excluded.

The **.exit** address notation, if enabled via [`MapAddress`](#mapaddress-address-newaddress), overrides this option.

#### `GeoIPExcludeUnknown 0|1|auto`

If this option is set to `auto`, then whenever any country code is set in [`ExcludeNodes`](#excludenodes-node-node) or [`ExcludeExitNodes`](#excludeexitnodes-node-node), all nodes with unknown country (`{??}` and possibly `{A1}`) are treated as excluded as well. If this option is set to `1`, then all unknown countries are treated as excluded in [`ExcludeNodes`](#excludenodes-node-node) and [`ExcludeExitNodes`](#excludeexitnodes-node-node). This option has no effect when a **GeoIP** file isn’t configured or can’t be found. (Default: `auto`)

#### `HSLayer2Nodes node,node,...`

A list of identity fingerprints, nicknames, country codes, and address patterns of nodes that are allowed to be used as the **second** hop in all client or service-side Onion Service circuits. This option mitigates attacks where the adversary runs middle nodes and induces your client or service to create many circuits, in order to discover your primary guard node. (Default: Any node in the network may be used in the second hop.)

(Example: `HSLayer2Nodes ABCD1234CDEF5678ABCD1234CDEF5678ABCD1234, {cc}, 255.254.0.0/8`)

{% hint style="info" %}
This option can appear multiple times: the values from multiple lines are spliced together.
{% endhint %}

When this is set, the resulting hidden service paths will look like:

C - G - L2 - M - Rend

C - G - L2 - M - HSDir

C - G - L2 - M - Intro

S - G - L2 - M - Rend

S - G - L2 - M - HSDir

S - G - L2 - M - Intro

where **C** is this client, **S** is the service, **G** is the Guard node, **L2** is a node from this option, and **M** is a random middle node. **Rend**, **HSDir**, and **Intro** point selection is not affected by this option.

This option may be combined with [`HSLayer3Nodes`](#hslayer3nodes-node-node) to create paths of the form:

C - G - L2 - L3 - Rend

C - G - L2 - L3 - M - HSDir

C - G - L2 - L3 - M - Intro

S - G - L2 - L3 - M - Rend

S - G - L2 - L3 - HSDir

S - G - L2 - L3 - Intro

[`ExcludeNodes`](#excludenodes-node-node) have higher priority than `HSLayer2Nodes`, which means that nodes specified in [`ExcludeNodes`](#excludenodes-node-node) will not be picked.

When either this option or [`HSLayer3Nodes`](#hslayer3nodes-node-node) are set, the `/16` subnet and node family restrictions are removed for hidden service circuits. Additionally, we allow the guard node to be present as the **Rend**, **HSDir**, and **IP** node, and as the hop before it. This is done to prevent the adversary from inferring information about our **guard**, **layer2**, and **layer3** node choices at later points in the path.

This option is meant to be managed by a Anon controller that selects and updates this set of nodes for you. Hence it does not do load balancing if fewer than `20` nodes are selected, and if no nodes in `HSLayer2Nodes` are currently available for use, Anon will not work.&#x20;

{% hint style="danger" %}
Please use extreme care if you are setting this option manually.
{% endhint %}

#### HSLayer3Nodes node,node,...

A list of identity fingerprints, nicknames, country codes, and address patterns of nodes that are allowed to be used as the **third** hop in all client and service-side Onion Service circuits. This option mitigates attacks where the adversary runs middle nodes and induces your client or service to create many circuits, in order to discover your primary or **Layer2** guard nodes. (Default: Any node in the network may be used in the third hop.)

(Example: `HSLayer3Nodes ABCD1234CDEF5678ABCD1234CDEF5678ABCD1234, {cc}, 255.254.0.0/8`)

{% hint style="info" %}
This option can appear multiple times: the values from multiple lines are spliced together.
{% endhint %}

When this is set by itself, the resulting hidden service paths will look like:

C - G - M - L3 - Rend

C - G - M - L3 - M - HSDir

C - G - M - L3 - M - Intro

S - G - M - L3 - M - Rend

S - G - M - L3 - HSDir

S - G - M - L3 - Intro

where **C** is this client, **S** is the service, **G** is the Guard node, **L2** is a node from this option, and **M** is a random middle node. **Rend**, **HSDir**, and **Intro** point selection is not affected by this option.

While it is possible to use this option by itself, it should be combined with [`HSLayer2Nodes`](#hslayer2nodes-node-node) to create paths of the form:

C - G - L2 - L3 - Rend

C - G - L2 - L3 - M - HSDir

C - G - L2 - L3 - M - Intro

S - G - L2 - L3 - M - Rend

S - G - L2 - L3 - HSDir

S - G - L2 - L3 - Intro

[`ExcludeNodes`](#excludenodes-node-node) have higher priority than `HSLayer3Nodes`, which means that nodes specified in [`ExcludeNodes`](#excludenodes-node-node) will not be picked.

When either this option or [`HSLayer2Nodes`](#hslayer2nodes-node-node) are set, the `/16` subnet and node family restrictions are removed for hidden service circuits. Additionally, we allow the guard node to be present as the **Rend**, **HSDir**, and **IP** node, and as the hop before it. This is done to prevent the adversary from inferring information about our **guard**, **layer2**, and **layer3** node choices at later points in the path.

This option is meant to be managed by a Anon controller that selects and updates this set of nodes for you. Hence it does not do load balancing if fewer than `20` nodes are selected, and if no nodes in `HSLayer3Nodes` are currently available for use, Anon will not work.&#x20;

{% hint style="danger" %}
Please use extreme care if you are setting this option manually.
{% endhint %}

#### `MiddleNodes node,node,...`

A list of identity fingerprints and country codes of nodes to use for "**middle**" hops in your normal circuits. Normal circuits include all circuits except for direct connections to directory servers. **Middle** hops are all hops other than **exit** and **entry**.

{% hint style="info" %}
This option can appear multiple times: the values from multiple lines are spliced together.
{% endhint %}

This is an experimental feature that is meant to be used by researchers and developers to test new features in the Anon network safely. Using it without care will strongly influence your anonymity. Other Anon features may not work with `MiddleNodes`. This feature might get removed in the future.

The **HSLayer2Node** and **HSLayer3Node** options override this option for onion service circuits, if they are set. The vanguards addon will read this option, and if set, it will set [`HSLayer2Nodes`](#hslayer2nodes-node-node) and [`HSLayer3Nodes`](#hslayer3nodes-node-node) to nodes from this set.

The [`ExcludeNodes`](#excludenodes-node-node) option overrides this option: any node listed in both `MiddleNodes` and [`ExcludeNodes`](#excludenodes-node-node) is treated as excluded. See the [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes.

#### `NodeFamily node,node,...`

The Anon servers, defined by their identity fingerprints, constitute a "**family**" of similar or co-administered servers, so never use any two of them in the same circuit. Defining a `NodeFamily` is only needed when a server doesn’t list the family itself (with [`MyFamily`](#myfamily-fingerprint-fingerprint-1)). **This option can be used multiple times**; each instance defines a separate family. In addition to nodes, you can also list IP address and ranges and country codes in **{curly braces}**. See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes.

#### `StrictNodes 0|1`

If `StrictNodes` is set to `1`, Anon will treat solely the [`ExcludeNodes`](#excludenodes-node-node) option as a requirement to follow for all the circuits you generate, even if doing so will break functionality for you (`StrictNodes` does not apply to [`ExcludeExitNodes`](#excludeexitnodes-node-node), [`ExitNodes`](#exitnodes-node-node), [`MiddleNodes`](#middlenodes-node-node), or [`MapAddress`](#mapaddress-address-newaddress)). If `StrictNodes` is set to `0`, Anon will still try to avoid nodes in the [`ExcludeNodes`](#excludenodes-node-node) list, but it will err on the side of avoiding unexpected errors. Specifically, `StrictNodes 0` tells Anon that it is okay to use an excluded node when it is necessary to perform relay reachability self-tests, connect to a hidden service, provide a hidden service to a client, fulfill a .exit request, upload directory information, or download directory information. (Default: `0`)

### DIRECTORY SERVER OPTIONS

The following options are useful only for directory servers. (Relays with enough bandwidth automatically become directory servers; see [`DirCache`](#dircache-0-or-1) for details.)

#### `DirCache 0|1`

When this option is set, Anon caches all current directory documents except extra info documents, and accepts client requests for them. If [`DownloadExtraInfo`](#downloadextrainfo-0-or-1) is set, cached extra info documents are also cached. Setting [`DirPort`](#dirport-address-port-or-auto-flags) is not required for `DirCache`, because clients connect via the [`ORPort`](#orport-address-port-or-auto-flags) by default. Setting either [`DirPort`](#dirport-address-port-or-auto-flags) or [`BridgeRelay`](#bridgerelay-0-or-1) and setting `DirCache` to `0` is not supported. (Default: `1`)

#### `DirPolicy policy,policy,...`

Set an entrance policy for this server, to limit who can connect to the directory ports. The policies have the same form as exit policies above, except that port specifiers are ignored. Any address not matched by some entry in the policy is accepted.

#### `DirPort [address:]PORT|auto [flags]`

If this option is non-zero, advertise the directory service on this port. Set it to "`auto`" to have Anon pick a port for you. This option can occur more than once, but only one advertised `DirPort` is supported: all but one `DirPort` must have the [`NoAdvertise`](#noadvertise) flag set. (Default: `0`)

The same flags are supported here as are supported by [`ORPort`](#orport-address-port-or-auto-flags). This port can only be IPv4.

As of 0.4.6.1-alpha, non-authoritative relays (see [`AuthoritativeDirectory`](#authoritativedirectory-0-or-1)) will not publish the `DirPort` but will still listen on it. Clients don’t use the `DirPorts` on relays, so it is safe for you to remove the `DirPort` from your [anonrc](#f-anonrc-file-file) configuration.

#### `DirPortFrontPage FILENAME`

When this option is set, it takes an HTML file and publishes it as "`/`" on the [`DirPort`](#dirport-address-port-or-auto-flags). Now relay operators can provide a disclaimer without needing to set up a separate webserver. There’s a sample disclaimer in **contrib/operator-tools/anon-exit-notice.html**.

#### `MaxConsensusAgeForDiffs N minutes|hours|days|weeks`

When this option is non-zero, Anon caches will not try to generate consensus diffs for any consensus older than this amount of time. If this option is set to `0`, Anon will pick a reasonable default from the current **networkstatus** document. You should not set this option unless your cache is severely low on disk space or CPU. If you need to set it, keeping it above `3` or `4` hours will help clients much more than setting it to `0`. (Default: `0`)

***

### DENIAL OF SERVICE MITIGATION OPTIONS

Anon has a series of built-in denial of service mitigation options that can be individually enabled/disabled and fine-tuned, but by default Anon directory authorities will define reasonable values for the network and no explicit configuration is required to make use of these protections.

The following is a series of configuration options for relays and then options for onion services and how they work.

The mitigations take place at relays, and are as follows:

1. If a single client address makes too many concurrent connections (this is configurable via [`DoSConnectionMaxConcurrentCount`](#dosconnectionmaxconcurrentcount-num)), hang up on further connections.
2. If a single client IP address (v4 or v6) makes circuits too quickly (default values are more than `3` per second, with an allowed burst of `90`, see [`DoSCircuitCreationRate`](#doscircuitcreationrate-num) and [`DoSCircuitCreationBurst`](#doscircuitcreationburst-num)) while also having too many connections open (default is `3`, see [`DoSCircuitCreationMinConnections`](#doscircuitcreationminconnections-num)), Anon will refuse any new circuit (`CREATE` cells) for the next while (random value between `1` and `2` hours).
3. If a client asks to establish a rendezvous point to you directly, ignore the request.

These defenses can be manually controlled by [**anonrc options**](#list-anonrc-options), but relays will also take guidance from consensus parameters using these same names, so there’s no need to configure anything manually. In doubt, do not change those values.

If any of the DoS mitigations are enabled, a heartbeat message will appear in your log at `NOTICE` level which looks like:

"DoS mitigation since startup: 429042 circuits rejected, 17 marked addresses. 2238 connections closed. 8052 single hop clients refused."

The following options are useful only for a public relay. They control the Denial of Service mitigation subsystem described above.

#### `DoSCircuitCreationEnabled 0|1|auto`

Enable circuit creation DoS mitigation. If set to `1` (enabled), Anon will cache client IPs along with statistics in order to detect circuit DoS attacks. If an address is positively identified, Anon will activate defenses against the address. See [`DoSCircuitCreationDefenseType`](#doscircuitcreationdefensetype-num) option for more details. This is a client to relay detection only. "`auto`" means use the consensus parameter. If not defined in the consensus, the value is `0`. (Default: `auto`)

#### `DoSCircuitCreationBurst NUM`

The allowed circuit creation burst per client IP address. If the circuit rate and the burst are reached, a client is marked as executing a circuit creation DoS. "`0`" means use the consensus parameter. If not defined in the consensus, the value is `90`. (Default: `0`)

#### `DoSCircuitCreationDefenseTimePeriod N seconds|minutes|hours`

The base time period in seconds that the DoS defense is activated for. The actual value is selected randomly for each activation from `N+1` to `3/2 * N`. "`0`" means use the consensus parameter. If not defined in the consensus, the value is `3600` seconds (1 hour). (Default: `0`)

#### `DoSCircuitCreationDefenseType NUM`

This is the type of defense applied to a detected client address. The possible values are:

1: No defense.

2: Refuse circuit creation for the [`DoSCircuitCreationDefenseTimePeriod`](#doscircuitcreationdefensetimeperiod-n-seconds-or-minutes-or-hours) period of time.

"`0`" means use the consensus parameter. If not defined in the consensus, the value is `2`. (Default: `0`)

#### `DoSCircuitCreationMinConnections NUM`

Minimum threshold of concurrent connections before a client address can be flagged as executing a circuit creation DoS. In other words, once a client address reaches the circuit rate and has a minimum of `NUM` concurrent connections, a detection is positive. "`0`" means use the consensus parameter. If not defined in the consensus, the value is `3`. (Default: `0`)

#### `DoSCircuitCreationRate NUM`

The allowed circuit creation rate per second applied per client IP address. If this option is `0`, it obeys a consensus parameter. If not defined in the consensus, the value is `3`. (Default: `0`)

#### `DoSConnectionEnabled 0|1|auto`

Enable the connection DoS mitigation. If set to `1` (enabled), for client address only, this allows Anon to mitigate against large number of concurrent connections made by a single IP address. "`auto`" means use the consensus parameter. If not defined in the consensus, the value is `0`. (Default: `auto`)

#### `DoSConnectionDefenseType NUM`

This is the type of defense applied to a detected client address for the connection mitigation. The possible values are:

1: No defense.

2: Immediately close new connections.

"`0`" means use the consensus parameter. If not defined in the consensus, the value is `2`. (Default: `0`)

#### `DoSConnectionMaxConcurrentCount NUM`

The maximum threshold of concurrent connection from a client IP address. Above this limit, a defense selected by [`DoSConnectionDefenseType`](#dosconnectiondefensetype-num) is applied. "`0`" means use the consensus parameter. If not defined in the consensus, the value is `100`. (Default: `0`)

#### `DoSConnectionConnectRate NUM`

The allowed rate of client connection from a single address per second. Coupled with the burst (see below), if the limit is reached, the address is marked and a defense is applied ([`DoSConnectionDefenseType`](#dosconnectiondefensetype-num)) for a period of time defined by [`DoSConnectionConnectDefenseTimePeriod`](#dosconnectionconnectdefensetimeperiod-n-seconds-or-minutes-or-hours). If not defined or set to `0`, it is controlled by a consensus parameter. (Default: `0`)

#### `DoSConnectionConnectBurst NUM`

The allowed burst of client connection from a single address per second. See the [`DoSConnectionConnectRate`](#dosconnectionconnectrate-num) for more details on this detection. If not defined or set to `0`, it is controlled by a consensus parameter. (Default: `0`)

#### `DoSConnectionConnectDefenseTimePeriod N seconds|minutes|hours`

The base time period in seconds that the client connection defense is activated for. The actual value is selected randomly for each activation from `N+1` to `3/2 * N`. If not defined or set to `0`, it is controlled by a consensus parameter. (Default: `24 hours`)

#### `DoSRefuseSingleHopClientRendezvous 0|1|auto`

Refuse establishment of rendezvous points for single hop clients. In other words, if a client directly connects to the relay and sends an `ESTABLISH_RENDEZVOUS` cell, it is silently dropped. "`auto`" means use the consensus parameter. If not defined in the consensus, the value is `0`. (Default: `auto`)

The following options are useful only for a exit relay.

#### `DoSStreamCreationEnabled 0|1|auto`

Enable the stream DoS mitigation. If set to `1` (enabled), Anon will apply rate limit on the creation of new streams and dns requests per circuit. "`auto`" means use the consensus parameter. If not defined in the consensus, the value is `0`. (Default: `auto`)

#### `DoSStreamCreationDefenseType NUM`

This is the type of defense applied to a detected circuit or stream for the stream mitigation. The possible values are:

1: No defense.

2: Reject the stream or resolve request.

3: Close the circuit creating too many streams.

"`0`" means use the consensus parameter. If not defined in the consensus, the value is `2`. (Default: `0`)

#### `DoSStreamCreationRate NUM`

The allowed rate of stream creation from a single circuit per second. Coupled with the burst (see below), if the limit is reached, actions can be taken against the stream or circuit ([`DoSStreamCreationDefenseType`](#dosstreamcreationdefensetype-num)). If not defined or set to `0`, it is controlled by a consensus parameter. If not defined in the consensus, the value is `100`. (Default: `0`)

#### `DoSStreamCreationBurst NUM`

The allowed burst of stream creation from a circuit per second. See the [`DoSStreamCreationRate`](#dosstreamcreationrate-num) for more details on this detection. If not defined or set to `0`, it is controlled by a consensus parameter. If not defined in the consensus, the value is `300`. (Default: `0`)

For onion services, mitigations are a work in progress and multiple options are currently available.

The introduction point defense is a rate limit on the number of introduction requests that will be forwarded to a service by each of its honest introduction point routers. This can prevent some types of overwhelming floods from reaching the service, but it will also prevent legitimate clients from establishing new connections.

The following options are per onion service:

#### `HiddenServiceEnableIntroDoSDefense 0|1`

Enable DoS defense at the intropoint level. When this is enabled, the rate and burst parameter (see below) will be sent to the intro point which will then use them to apply rate limiting for introduction request to this service.

The introduction point honors the consensus parameters except if this is specifically set by the service operator using this option. The service never looks at the consensus parameters in order to enable or disable this defense. (Default: `0`)

#### `HiddenServiceEnableIntroDoSBurstPerSec NUM`

The allowed client introduction burst per second at the introduction point. If this option is `0`, it is considered infinite and thus if [`HiddenServiceEnableIntroDoSDefense`](#hiddenserviceenableintrodosdefense-0-or-1) is set, it then effectively disables the defenses. (Default: `200`)

#### `HiddenServiceEnableIntroDoSRatePerSec NUM`

The allowed client introduction rate per second at the introduction point. If this option is `0`, it is considered infinite and thus if [`HiddenServiceEnableIntroDoSDefense`](#hiddenserviceenableintrodosdefense-0-or-1) is set, it then effectively disables the defenses. (Default: `25`)

The rate is the maximum number of clients a service will ask its introduction points to allow every seconds. And the burst is a parameter that allows that many within one second.

For example, the default values of `25` and `200` respectively means that for every introduction points a service has (default `3` but can be configured with [`HiddenServiceNumIntroductionPoints`](#hiddenservicenumintroductionpoints-num)), `25` **clients** per seconds will be allowed to reach the service and `200` at most within `1` second as a burst. This means that if `200` **clients** are seen within `1` second, it will take `8` seconds (`200/25`) for another client to be able to be allowed to introduce due to the rate of `25` per second.

This might be too much for your use case or not, fine tuning these values is hard and are likely different for each service operator.

"Why is this not helping reachability of the service?" Because the defenses are at the introduction point, an attacker can easily flood all introduction point rendering the service unavailable due to no client being able to pass through. But, the service itself is not overwhelmed with connetions allowing it to function properly for the few clients that were able to go through or other any services running on the same Anon instance.

The bottom line is that this protects the network by preventing an onion service to flood the network with new rendezvous circuits that is reducing load on the network.

A secondary mitigation is available, based on prioritized dispatch of rendezvous circuits for new connections. The queue is ordered based on effort a client chooses to spend at computing a proof-of-work function.

The following options are per onion service:

#### `HiddenServicePoWDefensesEnabled 0|1`

Enable proof-of-work based service DoS mitigation. If set to `1` (enabled), Anon will include parameters for an optional client puzzle in the encrypted portion of this hidden service’s descriptor. Incoming rendezvous requests will be prioritized based on the amount of effort a client chooses to make when computing a solution to the puzzle. The service will periodically update a suggested amount of effort, based on attack load, and disable the puzzle entirely when the service is not overloaded. (Default: `0`)

#### `HiddenServicePoWQueueRate NUM`

The sustained rate of rendezvous requests to dispatch per second from the priority queue. Has no effect when proof-of-work is disabled. If this is set to `0` there’s no explicit limit and we will process requests as quickly as possible. (Default: `250`)

#### `HiddenServicePoWQueueBurst NUM`

The maximum burst size for rendezvous requests handled from the priority queue at once. (Default: `2500`)

These options are applicable to both onion services and their clients:

#### `CompiledProofOfWorkHash 0|1|auto`

When proof-of-work DoS mitigation is active, both the services themselves and the clients which connect will use a dynamically generated hash function as part of the puzzle computation.

If this option is set to `1`, puzzles will only be solved and verified using the compiled implementation (about 20x faster) and we choose to fail rather than using a slower fallback. If it’s `0`, the compiler will never be used. By default, the compiler is always tried if possible but the interpreter is available as a fallback. (Default: `auto`)

See also [`--list-modules`](#list-modules), these proof of work options have no effect unless the "pow" module is enabled at compile time.

***

### DIRECTORY AUTHORITY SERVER OPTIONS

The following options enable operation as a directory authority, and control how Anon behaves as a directory authority. You should not need to adjust any of them if you’re running a regular relay or exit server on the public Anon network.

#### `AuthoritativeDirectory 0|1`

When this option is set to `1`, Anon operates as an authoritative directory server. Instead of caching the directory, it generates its own list of good servers, signs it, and sends that to the clients. Unless the clients already have you listed as a trusted directory, you probably do not want to set this option.

#### `BridgeAuthoritativeDir 0|1`

When this option is set in addition to [`AuthoritativeDirectory`](#authoritativedirectory-0-or-1), Anon accepts and serves server descriptors, but it caches and serves the main networkstatus documents rather than generating its own. (Default: `0`)

#### `V3AuthoritativeDirectory 0|1`

When this option is set in addition to [`AuthoritativeDirectory`](#authoritativedirectory-0-or-1), Anon generates **version 3** network statuses and serves descriptors, etc as described in `dir-spec.txt` file of **anonspec** (for Anon clients and servers running at least 0.2.0.x).

#### `AuthDirBadExit AddressPattern...`

**Authoritative directories only**. A set of address patterns for servers that will be listed as bad exits in any network status document this authority publishes, if [`AuthDirListBadExits`](#authdirlistbadexits-0-or-1) is set.

(The address pattern syntax here and in the options below is the same as for exit policies, except that you don’t need to say "`accept`" or "`reject`", and ports are not needed.)

#### `AuthDirMiddleOnly AddressPattern...`

**Authoritative directories only**. A set of address patterns for servers that will be listed as middle-only in any network status document this authority publishes, if [`AuthDirListMiddleOnly`](#authdirlistmiddleonly-0-or-1) is set.

#### `AuthDirFastGuarantee N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

**Authoritative directories only**. If non-zero, always vote the **Fast** flag for any relay advertising this amount of capacity or more. (Default: `100 KBytes`)

#### `AuthDirGuardBWGuarantee N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

**Authoritative directories only**. If non-zero, this advertised capacity or more is always sufficient to satisfy the bandwidth requirement for the **Guard** flag. (Default: `2 MBytes`)

#### `AuthDirHasIPv6Connectivity 0|1`

**Authoritative directories only**. When set to `0`, OR ports with an IPv6 address are not included in the authority’s votes. When set to `1`, IPv6 OR ports are tested for reachability like IPv4 OR ports. If the reachability test succeeds, the authority votes for the IPv6 [`ORPort`](#orport-address-port-or-auto-flags), and votes **Running** for the relay. If the reachability test fails, the authority does not vote for the IPv6 [`ORPort`](#orport-address-port-or-auto-flags), and does not vote **Running** (Default: `0`)

The content of the consensus depends on the number of voting authorities that set `AuthDirHasIPv6Connectivity`:

If no authorities set `AuthDirHasIPv6Connectivity 1`, there will be no IPv6 ORPorts in the consensus.

If a minority of authorities set `AuthDirHasIPv6Connectivity 1`, unreachable IPv6 ORPorts will be removed from the consensus. But the majority of IPv4-only authorities will still vote the relay as **Running**. Reachable IPv6 [`ORPort`](#orport-address-port-or-auto-flags) lines will be included in the consensus

If a majority of voting authorities set `AuthDirHasIPv6Connectivity 1`, relays with unreachable IPv6 ORPorts will not be listed as **Running**. Reachable IPv6 [`ORPort`](#orport-address-port-or-auto-flags) lines will be included in the consensus (To ensure that any valid majority will vote relays with unreachable IPv6 ORPorts not **Running**, 75% of authorities must set `AuthDirHasIPv6Connectivity 1`.)

#### `AuthDirInvalid AddressPattern...`

**Authoritative directories only**. A set of address patterns for servers that will never be listed as "**valid**" in any network status document that this authority publishes.

#### `AuthDirListBadExits 0|1`

**Authoritative directories only**. If set to `1`, this directory has some opinion about which nodes are unsuitable as exit nodes. (Do not set this to `1` unless you plan to list non-functioning exits as bad; otherwise, you are effectively voting in favor of every declared exit as an exit.)

#### `AuthDirListMiddleOnly 0|1`

**Authoritative directories only**. If set to `1`, this directory has some opinion about which nodes should only be used in the middle position. (Do not set this to `1` unless you plan to list questionable relays as "**middle only**"; otherwise, you are effectively voting against middle-only status for every relay.)

#### `AuthDirMaxServersPerAddr NUM`

**Authoritative directories only**. The maximum number of servers that we will list as acceptable on a single IP address. Set this to "`0`" for "**no limit**". (Default: `2`)

#### `AuthDirPinKeys 0|1`

**Authoritative directories only**. If non-zero, do not allow any relay to publish a descriptor if any other relay has reserved its <**Ed25519,RSA**> identity keypair. In all cases, Anon records every keypair it accepts in a journal if it is new, or if it differs from the most recently accepted pinning for one of the keys it contains. (Default: `1`)

#### `AuthDirReject AddressPattern...`

**Authoritative directories only**. A set of address patterns for servers that will never be listed at all in any network status document that this authority publishes, or accepted as an OR address in any descriptor submitted for publication by this authority.

#### `AuthDirRejectRequestsUnderLoad 0|1`

If set, the directory authority will start rejecting directory requests from non relay connections by sending a **503** error code if it is under bandwidth pressure (reaching the configured limit if any). Relays will always tried to be answered even if this is on. (Default: `1`)

#### `AuthDirBadExitCCs CC,...`

#### `AuthDirInvalidCCs CC,...`

#### `AuthDirMiddleOnlyCCs CC,...`

#### `AuthDirRejectCCs CC,...`

**Authoritative directories only**. These options contain a comma-separated list of country codes such that any server in one of those country codes will be marked as a bad exit/**invalid** for use, or **rejected** entirely.

#### `AuthDirSharedRandomness 0|1`

**Authoritative directories only**. Switch for the shared random protocol. If zero, the authority won’t participate in the protocol. If non-zero (default), the flag "**shared-rand-participate**" is added to the authority vote indicating participation in the protocol. (Default: `1`)

#### `AuthDirTestEd25519LinkKeys 0|1`

**Authoritative directories only**. If this option is set to `0`, then we treat relays as "**Running**" if their RSA key is correct when we probe them, regardless of their **Ed25519** key. We should only ever set this option to `0` if there is some major bug in **Ed25519** link authentication that causes us to label all the relays as not **Running**. (Default: `1`)

#### `AuthDirTestReachability 0|1`

**Authoritative directories only**. If set to `1`, then we periodically check every relay we know about to see whether it is running. If set to `0`, we vote **Running** for every relay, and don’t perform these tests. (Default: `1`)

#### `AuthDirVoteGuard node,node,...`

A list of identity fingerprints or country codes or address patterns of nodes to vote **Guard** for regardless of their uptime and bandwidth. See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes.

#### `AuthDirVoteGuardBwThresholdFraction FRACTION`

The **Guard** flag bandwidth performance threshold fraction that is the fraction representing who gets the **Guard** flag out of all measured bandwidth. (Default: `0.75`)

#### `AuthDirVoteGuardGuaranteeTimeKnown N seconds|minutes|hours|days|weeks`

A relay with at least this much weighted time known can be considered familiar enough to be a **Guard**. (Default: `8 days`)

#### `AuthDirVoteGuardGuaranteeWFU FRACTION`

A level of weighted fractional uptime (`WFU`) is that is sufficient to be a **Guard**. (Default: `0.98`)

#### `AuthDirVoteStableGuaranteeMinUptime N seconds|minutes|hours|days|weeks`

If a relay’s uptime is at least this value, then it is always considered stable, regardless of the rest of the network. (Default: `30 days`)

#### `AuthDirVoteStableGuaranteeMTBF N seconds|minutes|hours|days|weeks`

If a relay’s mean time between failures (`MTBF`) is least this value, then it will always be considered stable. (Default: `5 days`)

#### `BridgePassword Password`

If set, contains an HTTP authenticator that tells a bridge authority to serve all requested bridge information. Used by the (only partially implemented) "**bridge community**" design, where a community of bridge relay operators all use an alternate bridge directory authority, and their target user audience can periodically fetch the list of available community bridges to stay up-to-date. (Default: `not set`)

#### `ConsensusParams STRING`

`STRING` is a space-separated list of **key=value pairs** that Anon will include in the "**params**" line of its **networkstatus** vote. **This directive can be specified multiple times** so you don’t have to put it all on one line.

#### `DirAllowPrivateAddresses 0|1`

If set to `1`, Anon will accept server descriptors with arbitrary "**Address**" elements. Otherwise, if the address is not an IP address or is a private IP address, it will reject the server descriptor. Additionally, Anon will allow exit policies for private networks to fulfill **Exit** flag requirements. (Default: `0`)

#### `GuardfractionFile FILENAME`

**V3 authoritative directories only**. Configures the location of the **guardfraction** file which contains information about how long relays have been guards. (Default: **unset**)

#### `MinMeasuredBWsForAuthToIgnoreAdvertised N`

A total value, in abstract bandwidth units, describing how much measured total bandwidth an authority should have observed on the network before it will treat advertised bandwidths as wholly unreliable. (Default: `500`)

#### `MinUptimeHidServDirectoryV2 N seconds|minutes|hours|days|weeks`

Minimum uptime of a relay to be accepted as a hidden service directory by directory authorities. (Default: `96 hours`)

#### `RecommendedClientVersions STRING`

`STRING` is a comma-separated list of Anon versions currently believed to be safe for clients to use. This information is included in version 2 directories. If this is not set then the value of [`RecommendedVersions`](#recommendedversions-string) is used. When this is set then [`VersioningAuthoritativeDirectory`](#versioningauthoritativedirectory-0-or-1) should be set too.

#### `RecommendedServerVersions STRING`

`STRING` is a comma-separated list of Anon versions currently believed to be safe for servers to use. This information is included in version 2 directories. If this is not set then the value of [`RecommendedVersions`](#recommendedversions-string) is used. When this is set then [`VersioningAuthoritativeDirectory`](#versioningauthoritativedirectory-0-or-1) should be set too.

#### `RecommendedVersions STRING`

`STRING` is a comma-separated list of Anon versions currently believed to be safe. The list is included in each directory, and nodes which pull down the directory learn whether they need to upgrade. **This option can appear multiple times**: the values from multiple lines are spliced together. When this is set then [`VersioningAuthoritativeDirectory`](#versioningauthoritativedirectory-0-or-1) should be set too.

#### `MinimalAcceptedServerVersion STRING`

`STRING` is the oldest Anon version accepted by the directory authority for relays and bridge. Any older version will be rejected. (Default: `0.4.7.0-alpha-dev` although anon started at `0.4.9.0-alpha-dev` when it was forked)

#### `V3AuthDistDelay N seconds|minutes|hours`

**V3 authoritative directories only**. Configures the server’s preferred delay between publishing its consensus and signature and assuming it has all the signatures from all the other authorities. Note that the actual time used is not the server’s preferred time, but the consensus of all preferences. (Default: `5 minutes`)

#### `V3AuthNIntervalsValid NUM`

**V3 authoritative directories only**. Configures the number of **VotingIntervals** for which each consensus should be valid for. Choosing high numbers increases network partitioning risks; choosing low numbers increases directory traffic. Note that the actual number of intervals used is not the server’s preferred number, but the consensus of all preferences. Must be at least `2`. (Default: `3`)

#### `V3AuthUseLegacyKey 0|1`

If set, the directory authority will sign consensuses not only with its own signing key, but also with a "**legacy**" key and certificate with a different identity. This feature is used to migrate directory authority keys in the event of a compromise. (Default: `0`)

#### `V3AuthVoteDelay N seconds|minutes|hours`

**V3 authoritative directories only**. Configures the server’s preferred delay between publishing its vote and assuming it has all the votes from all the other authorities. Note that the actual time used is not the server’s preferred time, but the consensus of all preferences. (Default: `5 minutes`)

#### `V3AuthVotingInterval N minutes|hours`

**V3 authoritative directories only**. Configures the server’s preferred voting interval. Note that voting will actually happen at an interval chosen by consensus from all the authorities' preferred intervals. This time **SHOULD** divide evenly into a day. (Default: `1 hour`)

#### `V3BandwidthsFile FILENAME`

**V3 authoritative directories only**. Configures the location of the bandwidth-authority generated file storing information on relays measured bandwidth capacities. To avoid inconsistent reads, bandwidth data should be written to temporary file, then renamed to the configured filename. (Default: `unset`)

#### `VersioningAuthoritativeDirectory 0|1`

When this option is set to `1`, Anon adds information on which versions of Anon are still believed safe for use to the published directory. Each version 1 authority is automatically a versioning authority; version 2 authorities provide this service optionally. See [`RecommendedVersions`](#recommendedversions-string), [`RecommendedClientVersions`](#recommendedclientversions-string), and [`RecommendedServerVersions`](#recommendedserverversions-string).

***

### HIDDEN SERVICE OPTIONS

The following options are used to configure a hidden service. Some options apply per service and some apply for the whole Anon instance.

The next section describes the per service options that can only be set after the [`HiddenServiceDir`](#hiddenservicedir-directory) directive

#### PER SERVICE OPTIONS:

#### `HiddenServiceAllowUnknownPorts 0|1`

If set to `1`, then connections to unrecognized ports do not cause the current hidden service to close rendezvous circuits. (Setting this to `0` is not an authorization mechanism; it is instead meant to be a mild inconvenience to port-scanners.) (Default: `0`)

#### `HiddenServiceDir DIRECTORY`

Store data files for a hidden service in `DIRECTORY`. Every hidden service must have a separate directory. You may use this option multiple times to specify multiple services. If `DIRECTORY` does not exist, Anon will create it. Please note that you cannot add new Onion Service to already running Anon instance if **Sandbox** is enabled. (Note: in current versions of Anon, if `DIRECTORY` is a relative path, it will be relative to the current working directory of Anon instance, not to its [`DataDirectory`](#datadirectory-dir). **Do not rely on this behavior; it is not guaranteed to remain the same in future versions**.)

#### `HiddenServiceDirGroupReadable 0|1`

If this option is set to `1`, allow the filesystem group to read the hidden service directory and hostname file. If the option is set to `0`, only owner is able to read the hidden service directory. (Default: `0`) **Has no effect on Windows.**

#### `HiddenServiceExportCircuitID protocol`

The onion service will use the given protocol to expose the global circuit identifier of each inbound client circuit. The only protocol supported right now '**haproxy**'. This option is only for v3 services. (Default: `none`)

The **haproxy** option works in the following way: when the feature is enabled, the Anon process will write a header line when a client is connecting to the onion service. The header will look like this:

"PROXY TCP6 fc00:dead:beef:4dad::ffff:ffff ::1 65535 42\r\n"

We encode the "**global circuit identifier**" as the last 32-bits of the first IPv6 address. All other values in the header can safely be ignored. You can compute the global circuit identifier using the following formula given the IPv6 address "`fc00:dead:beef:4dad::AABB:CCDD`":

`global_circuit_id = (0xAA << 24) + (0xBB << 16) + (0xCC << 8) + 0xDD;`

In the case above, where the last 32-bits are `0xffffffff`, the global circuit identifier would be `4294967295`. You can use this value together with Anon’s control port to terminate particular circuits using their global circuit identifiers. For more information about this see **control-spec.txt**.

The **HAProxy** version 1 protocol is described in detail at <https://www.haproxy.org/download/1.8/doc/proxy-protocol.txt>

#### `HiddenServiceOnionBalanceInstance 0|1`

If set to `1`, this onion service becomes an **OnionBalance** instance and will accept client connections destined to an **OnionBalance** frontend. In this case, Anon expects to find a file named "**ob\_config**" inside the [`HiddenServiceDir`](#hiddenservicedir-directory) directory with content:

#### `MasterOnionAddress <frontend_onion_address>`

where <**frontend\_onion\_address**> is the onion address of the **OnionBalance** frontend (e.g. `wrxdvcaqpuzakbfww5sxs6r2uybczwijzfn2ezy2osaj7iox7kl7nhad.onion`).

#### `HiddenServiceMaxStreams N`

The maximum number of simultaneous streams (**connections**) per rendezvous circuit. The maximum value allowed is `65535`. (Setting this to `0` will allow an unlimited number of simultaneous streams.) (Default: `0`)

#### `HiddenServiceMaxStreamsCloseCircuit 0|1`

If set to `1`, then exceeding [`HiddenServiceMaxStreams`](#hiddenservicemaxstreams-n) will cause the offending rendezvous circuit to be torn down, as opposed to stream creation requests that exceed the limit being silently ignored. (Default: `0`)

#### `HiddenServiceNumIntroductionPoints NUM`

Number of introduction points the hidden service will have. You can’t have more than `20`. (Default: `3`)

#### `HiddenServicePort VIRTPORT [TARGET]`

Configure a virtual port `VIRTPORT` for a hidden service. **You may use this option multiple times**; each time applies to the service using the most recent [`HiddenServiceDir`](#hiddenservicedir-directory). By default, this option maps the virtual port to the same port on `127.0.0.1` over TCP. You may override the target port, address, or both by specifying a target of `addr`, `port`, `addr:port`, or `unix:path`. (You can specify an IPv6 target as `[addr]:port`. Unix paths may be quoted, and may use standard C escapes.) You may also have multiple lines with the same `VIRTPORT`: when a user connects to that `VIRTPORT`, one of the `TARGET`s from those lines will be chosen at random. Note that address-port pairs have to be comma-separated.

**HiddenServiceVersion 3** A list of rendezvous service descriptor versions to publish for the hidden service. Currently, only version 3 is supported. (Default: `3`)

***

### PER INSTANCE OPTIONS:

#### `HiddenServiceSingleHopMode 0|1`

**Experimental** - Non Anonymous Hidden Services on a Anon instance in [`HiddenServiceSingleHopMode`](#hiddenservicesinglehopmode-0-or-1) make one-hop (**direct**) circuits between the onion service server, and the introduction and rendezvous points. (Onion service descriptors are still posted using **3-hop** paths, to avoid onion service directories blocking the service.) This option makes every hidden service instance hosted by a Anon instance a **Single Onion Service**. **One-hop** circuits make **Single Onion** servers easily locatable, but clients remain location-anonymous. However, the fact that a client is accessing a **Single Onion** rather than a **Hidden Service** may be statistically distinguishable.

{% hint style="danger" %}
**WARNING**: Once a hidden service directory has been used by a Anon instance in [`HiddenServiceSingleHopMode`](#hiddenservicesinglehopmode-0-or-1), it can **NEVER** be used again for a hidden service. It is best practice to create a new hidden service directory, key, and address for each new **Single Onion Service** and **Hidden Service**. It is not possible to run **Single Onion Services** and **Hidden Services** from the same Anon instance: they should be run on different servers with different IP addresses.
{% endhint %}

[`HiddenServiceSingleHopMode`](#hiddenservicesinglehopmode-0-or-1) requires [`HiddenServiceNonAnonymousMode`](#hiddenservicenonanonymousmode-0-or-1) to be set to `1`. Since a **Single Onion** service is non-anonymous, you can not configure a [`SOCKSPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) on a Anon instance that is running in [`HiddenServiceSingleHopMode`](#hiddenservicesinglehopmode-0-or-1). Can not be changed while Anon is running. (Default: `0`)

#### `HiddenServiceNonAnonymousMode 0|1`

Makes hidden services non-anonymous on this Anon instance. Allows the non-anonymous [`HiddenServiceSingleHopMode`](#hiddenservicesinglehopmode-0-or-1). Enables direct connections in the server-side hidden service protocol. If you are using this option, you need to disable all client-side services on your Anon instance, including setting [`SOCKSPort`](#socksport-address-port-or-unix-path-or-auto-flags-isolation-flags) to "`0`". Can not be changed while Anon is running. (Default: `0`)

#### `PublishHidServDescriptors 0|1`

If set to `0`, Anon will run any hidden services you configure, but it won’t advertise them to the rendezvous directory. This option is only useful if you’re using a Anon controller that handles hidserv publishing for you. (Default: `1`)

***

### CLIENT AUTHORIZATION&#x20;

#### Service side:

To configure client authorization on the service side, the "`/authorized_clients/`" directory needs to exist. Each file in that directory should be suffixed with "**.auth**" (i.e. "`alice.auth`"; the file name is irrelevant) and its content format **MUST** be:

`::`

The supported are: "**descriptor**". The supported are: "**x25519**". The is the base32 representation of the raw key bytes only (`32 bytes` for `x25519`).

**Each file MUST contain one line only**. Any malformed file will be ignored. Client authorization will only be enabled for the service if Anon successfully loads at least one authorization file.

Note that once you've configured client authorization, anyone else with the address won't be able to access it from this point on. If no authorization is configured, the service will be accessible to anyone with the onion address.

Revoking a client can be done by removing their "**.auth**" file, however the revocation will be in effect only after the Anon process gets restarted or if a `SIGHUP` takes place.

#### Client side:

To access a v3 onion service with client authorization as a client, make sure you have [`ClientOnionAuthDir`](#clientonionauthdir-path) set in your [`anonrc`](#f-anonrc-file-file). Then, in the directory, create an **.auth\_private** file for the onion service corresponding to this key (i.e. '`bob_onion.auth_private`'). The contents of the **/.auth\_private** file should look like:

`<56-char-onion-addr-without-.onion-part>:descriptor:x25519:`

***

### TESTING NETWORK OPTIONS

The following options are used for running a testing Anon network.

#### `TestingTorNetwork 0|1`

If set to `1`, Anon adjusts default values of the configuration options below, so that it is easier to set up a testing Anon network. May only be set if non-default set of [`DirAuthorities`](#dirauthority-nickname-flags-ipv4address-dirport-fingerprint) is set. Cannot be unset while Anon is running. (Default: `0`)

{% code overflow="wrap" %}

```
DirAllowPrivateAddresses 1 EnforceDistinctSubnets 0 AuthDirMaxServersPerAddr 0 ClientBootstrapConsensusAuthorityDownloadInitialDelay 0 ClientBootstrapConsensusFallbackDownloadInitialDelay 0 ClientBootstrapConsensusAuthorityOnlyDownloadInitialDelay 0 ClientDNSRejectInternalAddresses 0 ClientRejectInternalAddresses 0 CountPrivateBandwidth 1 ExitPolicyRejectPrivate 0 ExtendAllowPrivateAddresses 1 V3AuthVotingInterval 5 minutes V3AuthVoteDelay 20 seconds V3AuthDistDelay 20 seconds TestingV3AuthInitialVotingInterval 150 seconds TestingV3AuthInitialVoteDelay 20 seconds TestingV3AuthInitialDistDelay 20 seconds TestingAuthDirTimeToLearnReachability 0 minutes MinUptimeHidServDirectoryV2 0 minutes TestingServerDownloadInitialDelay 0 TestingClientDownloadInitialDelay 0 TestingServerConsensusDownloadInitialDelay 0 TestingClientConsensusDownloadInitialDelay 0 TestingBridgeDownloadInitialDelay 10 TestingBridgeBootstrapDownloadInitialDelay 0 TestingClientMaxIntervalWithoutRequest 5 seconds TestingDirConnectionMaxStall 30 seconds TestingEnableConnBwEvent 1 TestingEnableCellStatsEvent 1
```

{% endcode %}

#### `TestingAuthDirTimeToLearnReachability N seconds|minutes|hours`

After starting as an authority, do not make claims about whether routers are Running until this much time has passed. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `30 minutes`)

#### `TestingAuthKeyLifetime N seconds|minutes|hours|days|weeks|months`

Overrides the default lifetime for a signing **Ed25519** TLS Link authentication key. (Default: `2 days`)

#### `TestingAuthKeySlop N seconds|minutes|hours`

#### `TestingBridgeBootstrapDownloadInitialDelay N`

Initial delay in seconds for how long clients should wait before downloading a bridge descriptor for a new bridge. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingBridgeDownloadInitialDelay N`

How long to wait (in seconds) once clients have successfully downloaded a bridge descriptor, before trying another download for that same bridge. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `10800`)

#### `TestingClientConsensusDownloadInitialDelay N`

Initial delay in seconds for when clients should download consensuses. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingClientDownloadInitialDelay N`

Initial delay in seconds for when clients should download things in general. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingClientMaxIntervalWithoutRequest N seconds|minutes`

When directory clients have only a few descriptors to request, they batch them until they have more, or until this amount of time has passed. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `10 minutes`)

#### `TestingDirAuthVoteExit node,node,...`

A list of identity fingerprints, country codes, and address patterns of nodes to vote Exit for regardless of their uptime, bandwidth, or exit policy. See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes. In order for this option to have any effect, [`TestingTorNetwork`](#testingtornetwork-0-or-1) has to be set.

#### `TestingDirAuthVoteExitIsStrict 0|1`

If True (`1`), a node will never receive the **Exit** flag unless it is specified in the [`TestingDirAuthVoteExit`](#testingdirauthvoteexit-node-node) list, regardless of its **uptime**, **bandwidth**, or **exit policy**.

In order for this option to have any effect, [`TestingTorNetwork`](#testingtornetwork-0-or-1) has to be set.

#### `TestingDirAuthVoteGuard node,node,...`

A list of identity fingerprints and country codes and address patterns of nodes to vote **Guard** for regardless of their **uptime** and **bandwidth**. See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes.

In order for this option to have any effect, [`TestingTorNetwork`](#testingtornetwork-0-or-1) has to be set.

#### `TestingDirAuthVoteGuardIsStrict 0|1`

If True (`1`), a node will never receive the **Guard** flag unless it is specified in the [`TestingDirAuthVoteGuard`](#testingdirauthvoteguard-node-node) list, regardless of its **uptime** and **bandwidth**.

In order for this option to have any effect, [`TestingTorNetwork`](#testingtornetwork-0-or-1) has to be set.

#### `TestingDirAuthVoteHSDir node,node,...`

A list of identity fingerprints and country codes and address patterns of nodes to vote **HSDir** for regardless of their **uptime** and [`DirPort`](#dirport-address-port-or-auto-flags). See [`ExcludeNodes`](#excludenodes-node-node) for more information on how to specify nodes.

In order for this option to have any effect, [`TestingTorNetwork`](#testingtornetwork-0-or-1) must be set.

#### `TestingDirAuthVoteHSDirIsStrict 0|1`

If True (`1`), a node will never receive the **HSDir** flag unless it is specified in the [`TestingDirAuthVoteHSDir`](#testingdirauthvotehsdir-node-node) list, regardless of its **uptime** and [`DirPort`](#dirport-address-port-or-auto-flags).

In order for this option to have any effect, [`TestingTorNetwork`](#testingtornetwork-0-or-1) must be set.

#### `TestingDirConnectionMaxStall N seconds|minutes`

Let a directory connection stall this long before expiring it. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `5 minutes`)

#### `TestingEnableCellStatsEvent 0|1`

If this option is set, then Anon controllers may register for `CELL_STATS` events. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingEnableConnBwEvent 0|1`

If this option is set, then Anon controllers may register for `CONN_BW` events. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingLinkCertLifetime N seconds|minutes|hours|days|weeks|months`

Overrides the default lifetime for the certificates used to authenticate our **X509** link cert with our **Ed25519** signing key. (Default: `2 days`)

#### `TestingLinkKeySlop N seconds|minutes|hours`

#### `TestingMinExitFlagThreshold N KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

Sets a lower-bound for assigning an exit flag when running as an authority on a testing network. Overrides the usual default lower bound of `4 KBytes`. (Default: `0`)

#### `TestingMinFastFlagThreshold N bytes|KBytes|MBytes|GBytes|TBytes|KBits|MBits|GBits|TBits`

Minimum value for the **Fast** flag. Overrides the ordinary minimum taken from the consensus when [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingMinTimeToReportBandwidth N seconds|minutes|hours`

Do not report our measurements for our maximum observed bandwidth for any time period that has lasted for less than this amount of time. Values over `1 day` have no effect. (Default: `1 day`)

#### `TestingServerConsensusDownloadInitialDelay N`

Initial delay in seconds for when servers should download consensuses. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingServerDownloadInitialDelay N`

Initial delay in seconds for when servers should download things in general. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

#### `TestingSigningKeySlop N seconds|minutes|hours`

"How early before the official expiration of a an **Ed25519** signing key do we replace it and issue a new key?" (Default: `3 hours` for **link** and **auth**; `1 day` for **signing**.)

#### `TestingV3AuthInitialDistDelay N seconds|minutes|hours`

Like [`V3AuthDistDelay`](#v3authdistdelay-n-seconds-or-minutes-or-hours), but for initial voting interval before the first consensus has been created. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `5 minutes`)

#### `TestingV3AuthInitialVoteDelay N seconds|minutes|hours`

Like [`V3AuthVoteDelay`](#v3authvotedelay-n-seconds-or-minutes-or-hours), but for initial voting interval before the first consensus has been created. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `5 minutes`)

#### `TestingV3AuthInitialVotingInterval N seconds|minutes|hours`

Like [`V3AuthVotingInterval`](#v3authvotinginterval-n-minutes-or-hours), but for initial voting interval before the first consensus has been created. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `30 minutes`)

#### `TestingV3AuthVotingStartOffset N seconds|minutes|hours`

Directory authorities offset voting start time by this much. Changing this requires that [`TestingTorNetwork`](#testingtornetwork-0-or-1) is set. (Default: `0`)

***

### NON-PERSISTENT OPTIONS

These options are not saved to the [**anonrc**](#f-anonrc-file-file) file by the "`SAVECONF`" controller command. Other options of this type are documented in **control-spec.txt**, section 5.4. End-users should mostly ignore them.

`__ControlPort`, `__DirPort`, `__DNSPort`, `__ExtORPort`, `__NATDPort`, `__ORPort`, `__SocksPort`, `__TransPort`&#x20;

These underscore-prefixed options are variants of the regular **Port** options. They behave the same, except they are not saved to the [**anonrc**](#f-anonrc-file-file) file by the controller’s `SAVECONF` command.

**`SIGNALS`** Anon catches the following signals:

**`SIGTERM`** Anon will catch this, clean up and sync to disk if necessary, and exit.

**`SIGINT`** Anon clients behave as with **`SIGTERM`**; but Anon servers will do a controlled slow shutdown, closing listeners and waiting `30 seconds` before exiting. (The delay can be configured with the [`ShutdownWaitLength`](#shutdownwaitlength-num) config option.)

**`SIGHUP`** The signal instructs Anon to reload its configuration (including closing and reopening logs), and kill and restart its helper processes if applicable.

**`SIGUSR1`** Log statistics about current connections, past connections, and throughput.

**`SIGUSR2`** Switch all logs to **loglevel** debug. You can go back to the old **loglevels** by sending a **`SIGHUP`**.

**`SIGCHLD`** Anon receives this signal when one of its helper processes has exited, so it can clean up.

**`SIGPIPE`** Anon catches this signal and ignores it.

**`SIGXFSZ`** If this signal exists on your platform, Anon catches and ignores it.

**`FILES`** **/etc/anon/anonrc** Default location of the configuration file.

**`$HOME/.anonrc`** Fallback location for anonrc, if /etc/anon/anonrc is not found.

**`/var/lib/anon/`** The Anon process stores keys and other data here.

#### `CacheDirectory/cached-certs`

Contains downloaded directory key certificates that are used to verify authenticity of documents generated by the Anon directory authorities.

#### `CacheDirectory/cached-consensus` and/or `cached-microdesc-consensus`

The most recent consensus network status document we’ve downloaded.

#### `CacheDirectory/cached-descriptors` and `cached-descriptors.new`

These files contain the downloaded router statuses. Some routers may appear more than once; if so, the most recently published descriptor is used. Lines beginning with `@`-signs are annotations that contain more information about a given router. The **.new** file is an append-only journal; when it gets too large, all entries are merged into a new cached-descriptors file.

#### `CacheDirectory/cached-extrainfo` and `cached-extrainfo.new`

Similar to **cached-descriptors**, but holds optionally-downloaded "**extra-info**" documents. Relays use these documents to send inessential information about **statistics**, **bandwidth history**, and **network health** to the authorities. They aren’t fetched by default. See [`DownloadExtraInfo`](#downloadextrainfo-0-or-1) for more information.

#### `CacheDirectory/cached-microdescs` and `cached-microdescs.new`

These files hold downloaded **microdescriptors**. Lines beginning with `@`-signs are annotations that contain more information about a given router. The **.new** file is an append-only journal; when it gets too large, all entries are merged into a new **cached-microdescs** file.

#### `DataDirectory/state`

Contains a set of persistent key-value mappings. These include:

• the current entry guards and their status.

• the current bandwidth accounting values.

• when the file was last written

• what version of Anon generated the state file

• a short history of bandwidth usage, as produced in the server descriptors.

#### `DataDirectory/sr-state`

**Authority only**. This file is used to record information about the current status of the **shared-random-value** voting state.

#### `CacheDirectory/diff-cache`

**Directory cache only**. Holds older consensuses and diffs from oldest to the most recent consensus of each type compressed in various ways. Each file contains a set of key-value arguments describing its contents, followed by a single **`NUL`** byte, followed by the main file contents.

#### `DataDirectory/control_auth_cookie`

This file can be used only when cookie authentication is enabled. Used for cookie authentication with the controller. Location can be overridden by the [`CookieAuthFile`](#cookieauthfile-path) configuration option. Regenerated on startup.

#### `DataDirectory/lock`

This file is used to prevent two Anon instances from using the same data directory. If access to this file is locked, data directory is already in use by Anon.

#### `DataDirectory/key-pinning-journal`

Used by authorities. A line-based file that records mappings between **RSA1024** and **Ed25519** identity keys. Authorities enforce these mappings, so that once a relay has picked an **Ed25519** key, stealing or factoring the **RSA1024** key will no longer let an attacker impersonate the relay.

#### `KeyDirectory/authority_identity_key`

A v3 directory authority’s master identity key, used to authenticate its signing key. Anon doesn’t use this while it’s running. The **anon-gencert** program uses this. If you’re running an authority, you should keep this key offline, and not put it in this file.

#### `KeyDirectory/authority_certificate`

**Only directory authorities use this file**. A v3 directory authority’s certificate which authenticates the authority’s current vote- and consensus-signing key using its master identity key.

#### `KeyDirectory/authority_signing_key`

**Only directory authorities use this file**. A v3 directory authority’s signing key that is used to sign votes and consensuses. Corresponds to the **authority\_certificate** cert.

#### `KeyDirectory/legacy_certificate`

As **authority\_certificate**; used only when [`V3AuthUseLegacyKey`](#v3authuselegacykey-0-or-1) is set. See documentation for [`V3AuthUseLegacyKey`](#v3authuselegacykey-0-or-1).

#### `KeyDirectory/legacy_signing_key`

As **authority\_signing\_key**: used only when [`V3AuthUseLegacyKey`](#v3authuselegacykey-0-or-1) is set. See documentation for [`V3AuthUseLegacyKey`](#v3authuselegacykey-0-or-1).

#### `KeyDirectory/secret_id_key`

A relay’s **RSA1024** permanent identity key, including private and public components. Used to sign router descriptors, and to sign other keys.

#### `KeyDirectory/ed25519_master_id_public_key`

The public part of a relay’s **Ed25519** permanent identity key.

#### `KeyDirectory/ed25519_master_id_secret_key`

The private part of a relay’s **Ed25519** permanent identity key. This key is used to sign the medium-term **Ed25519** signing key. This file can be kept offline or encrypted. If so, Anon will not be able to generate new signing keys automatically; you’ll need to use `anon --keygen` to do so.

#### `KeyDirectory/ed25519_signing_secret_key`

The private and public components of a relay’s medium-term `Ed25519` signing key. This key is authenticated by the `Ed25519` master key, which in turn authenticates other keys (and router descriptors).

#### `KeyDirectory/ed25519_signing_cert`

The certificate which authenticates "**ed25519\_signing\_secret\_key**" as having been signed by the **Ed25519** master key.

#### `KeyDirectory/secret_onion_key and secret_onion_key.old`

A relay’s **RSA1024** short-term onion key. Used to decrypt old-style ("**`TAP`**") circuit extension requests. The **.old** file holds the previously generated key, which the relay uses to handle any requests that were made by clients that didn’t have the new one.

#### `KeyDirectory/secret_onion_key_ntor and secret_onion_key_ntor.old`

A relay’s **Curve25519** short-term onion key. Used to handle modern ("**ntor**") circuit extension requests. The **.old** file holds the previously generated key, which the relay uses to handle any requests that were made by clients that didn’t have the new one.

#### `DataDirectory/fingerprint`

**Only used by servers**. Contains the fingerprint of the server’s RSA identity key.

#### `DataDirectory/fingerprint-ed25519`

**Only used by servers**. Contains the fingerprint of the server’s **Ed25519** identity key.

#### `DataDirectory/hashed-fingerprint`

**Only used by bridges**. Contains the hashed fingerprint of the bridge’s identity key. (That is, the hash of the hash of the identity key.)

#### `DataDirectory/approved-routers`

**Only used by authoritative directory servers**. Each line lists a status and an identity, separated by whitespace. Identities can be **hex-encoded** RSA fingerprints, or **base-64** encoded `Ed25519` public keys. See the **fingerprint** file in a Anon relay’s [`DataDirectory`](#datadirectory-dir) for an example fingerprint line. If the status is **!reject**, then descriptors from the given identity are rejected by this server. If it is **!invalid** then descriptors are accepted, but marked in the vote as not valid. If it is **!badexit**, then the authority will vote for it to receive a **BadExit** flag, indicating that it shouldn’t be used for traffic leaving the Anon network. If it is **!middleonly**, then the authority will vote for it to only be used in the middle of circuits. (Neither rejected nor invalid relays are included in the consensus.)

#### `DataDirectory/v3-status-votes`

**Only for v3 authoritative directory servers**. This file contains status votes from all the authoritative directory servers.

#### `CacheDirectory/unverified-consensus`

Contains a network consensus document that has been downloaded, but which we didn’t have the right certificates to check yet.

#### `CacheDirectory/unverified-microdesc-consensus`

Contains a **microdescriptor-flavored** network consensus document that has been downloaded, but which we didn’t have the right certificates to check yet.

#### `DataDirectory/unparseable-desc`

Onion server descriptors that Anon was unable to parse are dumped to this file. Only used for debugging.

#### `DataDirectory/router-stability`

**Only used by authoritative directory servers**. Tracks measurements for router **mean-time-between-failures** so that authorities have a fair idea of how to set their **Stable** flags.

#### `DataDirectory/stats/dirreq-stats`

Only used by directory caches and authorities. This file is used to collect directory request statistics.

#### `DataDirectory/stats/entry-stats`

Only used by servers. This file is used to collect incoming connection statistics by Anon entry nodes.

#### `DataDirectory/stats/bridge-stats`

Only used by servers. This file is used to collect incoming connection statistics by Anon bridges.

#### `DataDirectory/stats/exit-stats`

**Only used by servers**. This file is used to collect outgoing connection statistics by Anon exit routers.

#### `DataDirectory/stats/<missing_filename>`

**Only used by servers**. This file is used to collect buffer usage history.

#### `DataDirectory/stats/conn-stats`

**Only used by servers**. This file is used to collect approximate connection history (number of active connections over time).

#### `DataDirectory/stats/hidserv-stats`

**Only used by servers**. This file is used to collect approximate counts of what fraction of the traffic is hidden service rendezvous traffic, and approximately how many hidden services the relay has seen.

#### `DataDirectory/networkstatus-bridges`

**Only used by authoritative bridge directories**. Contains information about bridges that have self-reported themselves to the bridge authority.

#### `HiddenServiceDirectory/hostname`

The **.onion** domain name for this hidden service. If the hidden service is restricted to authorized clients only, this file also contains authorization data for all clients.

{% hint style="info" %}
The clients will ignore any extra subdomains prepended to a hidden service hostname. Supposing you have "**xyz.onion**" as your hostname, you can ask your clients to connect to "**[www.xyz.onion](http://www.xyz.onion)**" or "**irc.xyz.onion**" for virtual-hosting purposes.
{% endhint %}

#### `HiddenServiceDirectory/private_key`

Contains the private key for this hidden service.

#### `HiddenServiceDirectory/client_keys`

Contains authorization data for a hidden service that is only accessible by authorized clients.

#### `HiddenServiceDirectory/onion_service_non_anonymous`

This file is present if a hidden service key was created in [`HiddenServiceNonAnonymousMode`](#hiddenservicenonanonymousmode-0-or-1).


# Tutorials


# Anyone Services I

Setting Up Hidden Services on the Anyone Network

This guide gives an example and explains how to set up hidden services on the Anyone Network.\
\
There are several options to run **anon**. The following tabs explain how to install it as a Debian package using our APT repository or via command line tools using the NPM package.\
\
Alternatively see the page called [Install Anon in Docker](/relay/start/install-anon-on-linux/docker) to find Docker instructions. Or read the [Anon Client Releases](/sdk/native-sdk/releases) page where you'll find instructions and links to examples utilizing the Anyone Protocol [GitHub Releases](https://github.com/anyone-protocol/ator-protocol/releases).

{% tabs %}
{% tab title="NPM" %}

1. Install the `anyone-client` with `npm`, edit a custom `anonrc` and start the client with `npx`.

```bash
npm install @anyone-protocol/anyone-client
```

{% hint style="info" %}
For detailed instructions see:\
[Install NPM Package](/sdk/npm/install) \
[Run from CLI](broken://pages/WAoxArmmKj4oCpmDhO03)
{% endhint %}

2. Backup any existing configuration and create a custom anonrc:

```bash
mkdir -p ./anon
[ -f ./anon/anonrc ] && mv ./anon/anonrc ./anon/anonrc_$(date +"%Y%m%d_%H%M%S").bak
touch ./anon/anonrc
```

3. To be able to route traffic through anon, add some configuration to the `anonrc` file:

```bash
cat <<EOL | tee ./anon/anonrc
ORPort 0
ControlPort 0
SocksPort 127.0.0.1:9050
SocksPolicy accept 127.0.0.1
SocksPolicy reject *
DataDirectory ./anon/

HiddenServiceDir ./anon/anon_service/
HiddenServicePort 80 127.0.0.1:80
EOL
```

{% hint style="success" %}
[**HiddenServiceDir**](/sdk/native-sdk/manual#hiddenservicedir-directory)\
This directory will store hidden service data and keys. Ensure the specified directory has the correct permissions and is writable by anyone-client.

[**HiddenServicePort**](/sdk/native-sdk/manual#hiddenserviceport-virtport-target)\
This redirects traffic from the hidden service to the local nginx server on port 80.
{% endhint %}

4. Start the `anyone-client` with the custom `anonrc`:

```bash
npx anyone-client -f ./anon/anonrc
```

5. To get your service address (open a new terminal window and) check the `hostname` file located in `./anon/anon_service/`:

```bash
cat ./anon/anon_service/hostname
```

This file contains the hidden service address (your `.onion` address) for your hidden service.
{% endtab %}

{% tab title="APT " %}
Install the `anon` client as a service on Debian, edit the default `anonrc` and restart the `anon.service`.

1. Set up the Anyone Protocol apt repository and install the anon packages:

```bash
. /etc/os-release
sudo wget -qO- https://deb.en.anyone.tech/anon.asc | sudo tee /etc/apt/trusted.gpg.d/anon.asc
sudo echo "deb [signed-by=/etc/apt/trusted.gpg.d/anon.asc] https://deb.en.anyone.tech anon-live-$VERSION_CODENAME main" | sudo tee /etc/apt/sources.list.d/anon.list
```

```
sudo apt-get update --yes
sudo apt-get install anon --yes
```

{% hint style="info" %}
For detailed instructions see:\
[Install anon on Linux](/relay/start/install-anon-on-linux)\
[Install anon using the apt repository](/relay/start/install-anon-on-linux/apt)
{% endhint %}

2. Backup default configuration and create a custom `anonrc`:

```bash
[ -f /etc/anon/anonrc ] && mv /etc/anon/anonrc /etc/anon/anonrc_$(date +"%Y%m%d_%H%M%S").bak
touch /etc/anon/anonrc
```

3. To be able to route traffic through anon, add some configuration to the `anonrc` file:

```bash
sudo cat <<EOL | sudo tee /etc/anon/anonrc
ORPort 0
ControlPort 0
SocksPort 127.0.0.1:9050
SocksPolicy accept 127.0.0.1
SocksPolicy reject *
DataDirectory /var/lib/anon/

HiddenServiceDir /var/lib/anon/anon_service/
HiddenServicePort 80 127.0.0.1:80
EOL
```

4. Restart the `anon` service:

```bash
sudo systemctl restart anon.service
```

{% hint style="success" %}
[**HiddenServiceDir**](/sdk/native-sdk/manual#hiddenservicedir-directory)\
This directory will store hidden service data and keys. Ensure the specified directory has the correct permissions and is writable by the anon service.\
\
[**HiddenServicePort**](/sdk/native-sdk/manual#hiddenserviceport-virtport-target)\
This redirects traffic from the hidden service to the local nginx server on port 80.
{% endhint %}

5. To get your service address check the `hostname` file located in `./anon/anon_service/`:

```bash
sudo cat /var/lib/anon/anon_service/hostname
```

This file contains the hidden service address (your `.onion` address) for your onion service.
{% endtab %}
{% endtabs %}

## Install and Configure nginx to run a web server

In this example we'll be setting up a local web server with [Nginx](https://nginx.org) to host some content.

Install `nginx`:

```bash
 sudo apt update --yes
 sudo apt-get install nginx --yes
```

Start and Enable `nginx`:

```bash
sudo systemctl start nginx
sudo systemctl enable nginx
```

Create an `index.html` in `/var/www/html` file as a basic test:

```bash
echo "Welcome to my Anyone Anon Service" | sudo tee /var/www/html/index.html
```

Create a new nginx configuration file for your service:

```bash
sudo nano /etc/nginx/sites-available/anon_service
```

Paste the following configuration  and save to route requests to your anon service:

```
server {
    listen 127.0.0.1:80;
    server_name localhost;

    root /var/www/html;
    index index.html;

    location / {
        try_files $uri $uri/ =404;
    }
}
```

Link the configuration to the `sites-enabled` directory:

```bash
sudo ln -s /etc/nginx/sites-available/anon_service /etc/nginx/sites-enabled/
```

Reload `nginx` to apply the changes:

```bash
sudo systemctl reload nginx
```

Test the rechability of the web server locally with `curl`:

```bash
curl "http://127.0.0.1:80"
```

Test the reachability of the web server's hostname, located in `./anon/anon_service/hostname`, using `curl --socks5-hostname`:

```bash
curl --socks5-hostname 127.0.0.1:9050 "http://$(cat ./anon/anon_service/hostname)"
```


# Anyone Services II

Setting Up Services on the Anyone Network

## Integrate SvelteKit with nginx, anon, and anyone-client

This is a follow up from [Anon Services I](/sdk/native-sdk/tutorials/services1), where we'll give an example of another application set up as a service on the Anyone Network.

"Svelte is a UI framework that uses a compiler to let you write breathtakingly concise components that do minimal work in the browser, using languages you already know — HTML, CSS and JavaScript. **It’s a love letter to web development.**

But don’t take our word for it. Developers consistently rank Svelte as the framework they’re most excited about using."

\- [https://svelte.dev](https://svelte.dev/)<br>

Let's start!

**If you haven't followed the steps in the** [**previous chapter**](/sdk/native-sdk/tutorials/services1)**, go ahead and do so before you continue following along in the instructions below.**

### Set up nginx for SvelteKit

Create a new nginx configuration for the Svelte service:

```bash
sudo nano /etc/nginx/sites-available/anon_service_svelte
```

Add this configuration to route requests to the Svelte app:

```
server {
    listen 127.0.0.1:5173;
    server_name localhost;

    root /var/www/my-svelte-anon-app/build;
    allow all;
    index index.js;

    location / {
        try_files $uri $uri/ =404;
    }
}
```

Enable Svelte and Reload nginx:

```bash
sudo ln -s /etc/nginx/sites-available/anon_service_svelte /etc/nginx/sites-enabled/
sudo systemctl reload nginx
```

### Configure anyone-client and anon for Svelte

Add port mapping for Svelte to existing `anonrc` configuration:

{% tabs %}
{% tab title="anyone-client" %}
If you followed the steps in [Anon Services I](/sdk/native-sdk/tutorials/services1), we created our custom anonrc in the `./anon` folder. Append the port mapping to the configuration with this command:

```bash
cat <<EOL | tee -a ./anon/anonrc
HiddenServicePort 5173 127.0.0.1:5173
EOL
```

{% endtab %}

{% tab title="anon.service" %}
With the Debian package, the `anon.service` stores the default `anonrc` in `/etc/anon/`.\
Append the port mapping to the configuration with this command and then reload the service:

```bash
cat <<EOL | tee -a /etc/anon/anonrc
HiddenServicePort 5173 127.0.0.1:5173
EOL
```

Reload the `anon.service`:

```bash
sudo systemctl reload anon.service
```

{% endtab %}
{% endtabs %}

### Set up and build the SvelteKit application

Create a project directory:

```bash
mkdir -p ~/anyone
cd ~/anyone
```

Initialize the project:

```bash
npx sv create my-svelte-anon-app
```

See SvelteKit documentation for more information about setting up projects.\
\
We chose these options for the example:

```
┌  Welcome to the Svelte CLI! (v0.6.1)
│
◇  Which template would you like?
│  SvelteKit minimal
│
◇  Add type checking with Typescript?
│  Yes, using Typescript syntax
│
◆  Project created
│
◇  What would you like to add to your project? (use arrow keys / space bar)
│  none
│
◇  Which package manager do you want to install dependencies with?
│  npm
│
◇  Successfully installed dependencies
│
◇  Project next steps ─────────────────────────────────────────────────────╮
│                                                                          │
│  1: cd my-svelte-anon-app                                                │
│  2: git init && git add -A && git commit -m "Initial commit" (optional)  │
│  3: npm run dev -- --open                                                │
│                                                                          │
│  To close the dev server, hit Ctrl-C                                     │
│                                                                          │
│  Stuck? Visit us at https://svelte.dev/chat                              │
│                                                                          │
├──────────────────────────────────────────────────────────────────────────╯
│
└  You're all set!
```

Install dependencies:

```bash
cd my-svelte-anon-app
npm install
```

Configure the SvelteKit Node Adapter:

```bash
npm install -D @sveltejs/adapter-node
```

Edit the `svelte.config.js` file located in your project folder.\
Change the `import` line to import the new `adapter-node`:

```
import adapter from '@sveltejs/adapter-node';
```

Load environment variables:

```bash
npm i dotenv
```

Add a `.env` file with `PORT` and `HOSTNAME`:

```bash
cat <<EOL | tee .env
PORT=5173
HOST=127.0.0.1
EOL
```

Build the project:

```bash
npm run build
#systemctl reload nginx
```

Move the build output to /var/www/my-svelte-anon-app:

```bash
sudo mkdir -p /var/www/my-svelte-anon-app
sudo cp -r build/ /var/www/my-svelte-anon-app/
```

### Testing the Svelte-based anon service

Confirm that the app is accessible locally at `http://127.0.0.1:5173`:

```bash
curl http://127.0.0.1:5173
```

Access the service via SOCKS5:

{% tabs %}
{% tab title="anyone-client" %}
Hostname located at: `./anon/anon_service/hostname`

```bash
curl --socks5-hostname 127.0.0.1:9050 "http://$(cat ./anon/anon_service/hostname):5173"
```

{% endtab %}

{% tab title="anon.service" %}
Hostname located at: `/var/lib/anon/anon_service/hostname`

```bash
curl --socks5-hostname 127.0.0.1:9050 "http://$(cat /var/lib/anon/anon_service/hostname):5173"
```

{% endtab %}
{% endtabs %}


# iOS SDK \[Beta]

{% hint style="warning" %}
The iOS SDK is pre-live, and is not currently available as a named Swift package or CocoaPods library. However, it is functional, and can be installed manually from GitHub via CocoaPods.&#x20;
{% endhint %}

[AnyoneKit](https://github.com/anyone-protocol/AnyoneKit/tree/pure_pod) is a set of libraries for embedding the Anyone Client in your iOS application. It is an Objective-C dependancy, but can be configured to be used in applications written in Swift. Check out the README on GitHub to find out more and see examples in-code.&#x20;

{% embed url="<https://github.com/anyone-protocol/AnyoneKit/tree/pure_pod>" %}


# CocoaPods install guide

The AnyoneKit can be installed via [CocoaPods](https://cocoapods.org/) - a popular Swift / Objective-C dependancy manager.&#x20;

#### Initializing CocoaPods

From your Xcode project, first verify that CocoaPods is installed

```
pod --version
```

If this returns `Command Not Found: pod` you can install CocoaPods using Ruby

```
sudo gem install cocoapods
```

Once again, verify that you have a working pod version! From there, within your Xcode project directory, initialize CocoaPods:

```
pod init
```

This should create a file called `Podfile` in your working directory.

#### Importing AnyoneKit&#x20;

From the Podfile, within the **target** section, add the AnyoneKit pod (for now, the GitHub repo must be specified)

```ruby
target 'YourApp' do
  pod 'AnyoneKit', :git => 'https://github.com/anyone-protocol/AnyoneKit.git'
end
```

After these configurations are set, start the installation process

```
pod install
```

You should then be able to use. See some examples within the [GitHub repo](https://github.com/anyone-protocol/AnyoneKit/tree/pure_pod/Example) to explore more ahead of the official iOS SDK Release.&#x20;


# API reference


# REST

The Anyone Network comes with a series of public REST APIs accessible by anyone who wants to investigate the live status of the network or their specific relay. This API complements the older Arweave metrics dumps that can be investigated by GraphQL requests (section coming soon).

{% hint style="info" %}
The official domain for our technical endpoints is **<https://anyone.tech>**

And the API is accessible at **<https://api.ec.anyone.tech>**
{% endhint %}

## Main API Specification

### Network-Wide API

#### Total Active Relays (Latest) <https://api.ec.anyone.tech/total-relays-latest>

```json
{
all: Total number of relays visible in latest consensus file,
offline: Relays recently running but currently offline,
online: Relays currently online
}
```

#### Total Active Relays (Over Time) <https://api.ec.anyone.tech/total-relays>

```
{
all[]: Total relays in latest consensus file over time (hourly),
offline[]:  Total relays recently offline over time (hourly),
online[]:  Total relays online over time (hourly)
}
```

#### **Total Network Bandwidth** [https://api.ec.anyone.tech/total-observed-bandwidth-latest ](<https://api.ec.anyone.tech/total-observed-bandwidth-latest >)

```
{
all: Sum of observed bandwidth for all relays in consensus file.
offline: Sum of observed bandwidth for all recently offline relays.
online: Sum of observed bandwidth for all offline relays
}
```

#### **Total Network Bandwidth (Over Time)** [**https://api.ec.anyone.tech/total-observed-bandwidth**](https://api.ec.anyone.tech/total-observed-bandwidth-latest)

```
{
all: Sum of observed bandwidth for all relays in consensus file over time.
offline: Sum of observed bandwidth for all recently offline relays over time.
online: Sum of observed bandwidth for all offline relays over time. 
}
```

Additional parameters to be appended at the end of the query

```
from: T – start time (s, m, d)
to: T – end time (s, m, d)
interval: interval 

Example: https://api-dev.dmz.ator.dev/total-relays?from=3d&to=now&interval=12h
```

#### Relay Map <https://api.ec.anyone.tech/relay-map>

```
[ // list of all relays as H3 datapoints 
    {
    "index: Unique H3 Hex ID
    "relayCount": Number of relays situated in the area of this cell
    "geo": Center of cell coordinates
    "boundary"[]: Cell boundary coordinates
    },
]
```

### Per-User Search&#x20;

#### **Relay Lookup** [**https://api.ec.anyone.tech/relays/**](<https://api.ec.anyone.tech/relays/ >)

```
{
"fingerprint": fingerprint of the relay,
"running": whether the relay is running,
"consensus_weight": Consensus weight score 
}
```

#### **Anon Check (API)** <https://check.en.anyone.tech/>[api/ip](https://check.en.anyone.tech/api/ip)

```
{
isAnon: Whether the un
IP: Your IP address visible to external sites
}
```

#### Anon Check (UI) [https://check.en.anyone.tech](https://check.en.anyone.tech/)

```
(Visual) Tells you whether you have routed through Anon.
```

### POST APIs

#### Hardware Authentication Endpoint [**https://api.ec.anyone.tech/relays**](<https://api.ec.anyone.tech/relay/ >)

### Additional API Endpoints

#### Current Status

#### All-Time Rewards

Retrieves the all-time earned rewards for a given wallet across all their relays.

```
https://relay-api.anyone.io/api/rewards/all-time/<wallet>
```

#### Relays Associated to One Wallet

Returns an object with all of the relays associated to one wallet. Used for integration with the Moken DePIN tracker.

```
https://relay-api.anyone.io/api/miners/<wallet>
```

Output:

```
[{
    "deviceId", // fingerprint 
    "type": "ANYONE", // fixed: project name 
    "friendlyName", // relay nickname 
  },
```

#### Rewards in Latest Epoch

Returns an object with the amount of tokens earnt by a relay in the last epoch, and epoch details

```
https://relay-api.anyone.io/api/rewards/<fingerprint>
```

Output:

```
{
    "date", // date and timestamp of epoch 
    "amount": // amount of tokens
    "tokenSymbol", // fixed: ANYONE
},
```

### Other Environments

To search for your relay in the **stage** environment:\
**🔗** [**https://api-stage.ec.anyone.tech** ](<https://api-stage.ec.anyone.tech >)


# \[Future] GraphQL


# Tracking the Protocol

A reference for portfolio trackers and other supplementary tools to track information in the protocol, such as staking and locked tokens.

### Tracking Staked Balance

The total tokens staked by a wallet can be called from a single read function of the protocol EVM contract on Ethereum Mainnet. It's contract address is as below and the source code can be found [here](https://github.com/anyone-protocol/hodler/blob/main/contracts/HodlerV5.sol).&#x20;

{% code title="Ethereum Mainnet Hodler Contract Address" %}

```
0x0d9a1ca7bc756ae009672db626cde3c9bef583ef
```

{% endcode %}

Note that the staked tokens do not include tokens that have been unstaked and are under the cooldown period before they can be withdrawn.&#x20;

The value can be fetched by calling the `getStake` function which returns a uint256 value. Note that $ANYONE has 18 decimals.&#x20;

{% code title="Function to Query Total Staked" %}

```
getStake(address _address); 
```

{% endcode %}

{% code title="ABI Reference for Total Staked function in Hodler" %}

```json
[
	{
			"inputs": [
				{
					"internalType": "address",
					"name": "_address",
					"type": "address"
				}
			],
			"name": "getStake",
			"outputs": [
				{
					"internalType": "uint256",
					"name": "",
					"type": "uint256"
				}
			],
			"stateMutability": "view",
			"type": "function"
		}
]
```

{% endcode %}

See an example code snippet for fetching this values with ethers.js:

```javascript
const provider;
const abi;
// Set provider URL and an abi JSON 

let address = 0xabc123; // Set target address 
const protocolAddress = '0x0d9a1ca7bc756ae009672db626cde3c9bef583ef';
const protocolContract = new ethers.Contract(protocolAddress, abi, provider);

let totalStaked = await protocolContract.getStake(<address>); 
```

*Last Updated: 29-Dec-2025*


# Integrations


# Monero CLI

Using Monero CLI Wallet with Anyone Network.

This guide shows how to run Monero CLI with all outbound RPC traffic routed through the Anyone network, ensuring no direct daemon connections leak your real network identity.

#### 1 - Download and extract Monera CLI

Download the official Monero CLI binaries for your system from <https://www.getmonero.org/downloads/> and extract them.

```
wget https://downloads.getmonero.org/cli/linux64
tar -xvf linux64
```

This creates a directory similar to: monero-x86\_64-linux-gnu-v0.18.4.5/

#### 2 - Start Anyone client

Start the Anyone anonymizing overlay so the local SOCKS5 proxy is available, and confirm the service is running successfully.

```
sudo systemctl start anon
systemctl status anon
```

<figure><img src="/files/961YMc0yPtejWsoDTt3t" alt=""><figcaption></figcaption></figure>

#### 3 - Navigate to the Monero CLI Directory

All Monero CLI commands must be executed from the extracted binaries directory.

Launch the Monero wallet with:

* SOCKS proxy enabled
* Remote daemon

```
cd ~/monero-x86_64-linux-gnu-v0.18.4.5

./monero-wallet-cli \
  --proxy 127.0.0.1:9050 \
  --daemon-address opennode.xmr-tw.org:18089 \
  --daemon-ssl-allow-any-cert
```

What this does:

* All daemon communication is routed through Anyone
* No direct RPC connections leave your machine

#### 4 - Open or Create Wallet

When prompted:

* Enter a wallet name (existing or new)
* Enter wallet password

The wallet will load and connect to the remote daemon.

<figure><img src="/files/biT9DM928mzCRKdXc1dV" alt=""><figcaption></figcaption></figure>

#### 5 - Verify Traffic Is Routed Through Anyone

Verify Traffic Is Routed Through Anyone with a TCP dump. Keep this terminal running while you trigger wallet activity in the other terminal.

```
sudo tcpdump -i any port 9050 -nn
```

Now return to the wallet terminal and run:&#x20;

```
refresh
status
rescan_bc
```

<figure><img src="/files/EnGNqJ4V3m7xnnXm0fgT" alt="" width="563"><figcaption></figcaption></figure>

Expected Result:&#x20;

* You should only see traffic between local address and the Anon SOCKS port (9050).
* You should not see direct connections to the RPC IP.

This confirms all Monero RPC traffic is passing through Anyone.

<figure><img src="/files/nrGeQjD92XtpFcoObojQ" alt=""><figcaption></figcaption></figure>


# Use Sepolia Anon RPC

We are now opening community testing for our first hidden service RPC node, targeted at the **Sepolia Testnet** network.&#x20;

A hidden RPC is one that is hosted completely anonymously within the Anyone Network. The only way to access and use the RPC is by running the Anyone client. The RPC is identified by a long form hidden address, which for testing purposes is&#x20;

```
http://anonrpchns3ehsytpjg6xjspjlfpuwzknwosc4fvbc2y6ty5ao2ldbyd.anon
```

As part of this testing, you can import this RPC link as a 'custom network option' for Sepolia within popular wallets such as Metamask and Rabby. Follow the steps below to get involved!

### Using the Hidden RPC for the Sepolia Network

#### 1 - Start the Anyone Client Locally

Its key to have the Anyone client running locally, as that is the only way to access the RPC. Running the client as a system-wide proxy will allow the .anon address to resolve from your wallet. Follow the pages below to get connected:

{% content-ref url="/pages/FF3XWni6VUKhyXkecIYM" %}
[Connect to Anyone](/connect)
{% endcontent-ref %}

#### 2 - Configure your Sepolia Network Settings

From your chosen wallet, add the Sepolia Network if it is not already available (or reconfigure it if it is) and input the following settings:

```
Chain ID: 11155111
Network name: Sepolia
RPC URL: http://anonrpchns3ehsytpjg6xjspjlfpuwzknwosc4fvbc2y6ty5ao2ldbyd.anon
Currency symbol: ETH
Block Explorer: https://sepolia.etherscan.io

```

Here's an example of those fields filled from Rabby Wallet:

<figure><img src="/files/XqMQdH2HvWetO7VxkBun" alt="" width="375"><figcaption></figcaption></figure>

So long as the Anyone Client is running and has bootstrapped a circuit within the network, you will then be able to read balances and submit transactions to Sepolia just as you normally would from your wallet!&#x20;


# Proxy AI API Request

Sending anonymous requests to any AI providers API over Anyone socks5 proxy using npm

{% tabs %}
{% tab title="JavaScript" %}

1. Install the anyone-client [npm](https://www.npmjs.com/package/@anyone-protocol/anyone-client) package:

{% code overflow="wrap" %}

```bash
npm install @anyone-protocol/anyone-client
```

{% endcode %}

2. Save the code to file `sendrequest.js` and edit highlighted `const` variables to match your API.
   1. `const API_URL = 'https://inference.asicloud.cudos.org/v1/chat/completions';`&#x20;
   2. `const PROVIDER_API_KEY = 'PROVIDER_API_KEY';`
   3. `const MODEL = 'asi1-mini';`
   4. `const MESSAGE = 'Hello Anyone!';`

{% code expandable="true" %}

```js
const { Process, Socks } = require('@anyone-protocol/anyone-client');

async function main() {
    try {
        // Start the anyone-client proxy
        const anon = new Process({ displayLog: false, socksPort: 9050 });
        const socks = new Socks(anon);
        await anon.start();

        const API_URL = 'https://inference.asicloud.cudos.org/v1/chat/completions';
        const PROVIDER_API_KEY = 'PROVIDER_API_KEY';
        const MODEL = 'asi1-mini';
        const MESSAGE = 'Hello Anyone!';

        // Create the JSON payload
        const payload = {
            model: MODEL,
            messages: [
                {
                    role: 'user',
                    content: MESSAGE,
                },
            ],
        };

        // Set up the API request headers
        const headers = {
            Authorization: `Bearer ${PROVIDER_API_KEY}`,
            'Content-Type': 'application/json',
        };

        // Make the request
        const response = await socks.post(API_URL, payload, { headers });
        console.log(`\nSending: ${payload.content, ( MESSAGE )}`);

        // Extract and log the response
        console.log(`\nResponse: ${JSON.stringify(response.data.choices[0].message.content, null, 2)}\n`);

        // Stop the anyone-client proxy
        await anon.stop();

    } catch (error) {
        console.error('Error:', error);
    }
}

main();
```

{% endcode %}

3. Run the script: `node sendrequest.js`

<figure><img src="/files/tFsTUeHXuZNRLZf0bHKY" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Connect to Anyone

For end users: usage, applications, no relay setup

<table data-view="cards" data-full-width="true"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center">Linux</td><td><a href="/files/U51XpOMEY7jUIfYVbjVv">/files/U51XpOMEY7jUIfYVbjVv</a></td><td><a href="/pages/2OOyxBxxNWfHULaLY2z2">/pages/2OOyxBxxNWfHULaLY2z2</a></td></tr><tr><td align="center">macOS</td><td><a href="/files/2OeVM5FzwDjJcoSwBWNe">/files/2OeVM5FzwDjJcoSwBWNe</a></td><td><a href="/pages/3lQweBeXESObsDuxOswF">/pages/3lQweBeXESObsDuxOswF</a></td></tr><tr><td align="center">Windows</td><td><a href="/files/baOsz6yUUnPX4ICsDu1S">/files/baOsz6yUUnPX4ICsDu1S</a></td><td><a href="/pages/G9iP6SEzVyBpVWq3n5pc">/pages/G9iP6SEzVyBpVWq3n5pc</a></td></tr></tbody></table>

<table data-view="cards" data-full-width="true"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center">Android</td><td data-object-fit="cover"><a href="/files/Ku2ud4jw2Y8isZZkOign">/files/Ku2ud4jw2Y8isZZkOign</a></td><td><a href="/pages/DLbgxWkQl4VruYOaX9u8">/pages/DLbgxWkQl4VruYOaX9u8</a></td></tr><tr><td align="center">iOS</td><td><a href="/files/vwA5IMImKb3MrbkFC38A">/files/vwA5IMImKb3MrbkFC38A</a></td><td><a href="/pages/cXrpddgP16as2sjI2ElQ">/pages/cXrpddgP16as2sjI2ElQ</a></td></tr></tbody></table>

<table data-card-size="large" data-view="cards" data-full-width="true"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center">Through Hardware</td><td data-object-fit="fill"><a href="/files/xAGQSTO4hAzgwQTHKzND">/files/xAGQSTO4hAzgwQTHKzND</a></td><td><a href="/pages/rSyrCAXYLiUbEJSkqcMa">/pages/rSyrCAXYLiUbEJSkqcMa</a></td></tr><tr><td align="center">Public Proxies</td><td><a href="/files/Uzp8WgoHM0KGGrBY4DTC">/files/Uzp8WgoHM0KGGrBY4DTC</a></td><td><a href="/pages/NO0K3B5t9PfctDEcRYUh">/pages/NO0K3B5t9PfctDEcRYUh</a></td></tr></tbody></table>

***

{% content-ref url="/pages/vHAXx7Cw1XfV74uhD2dZ" %}
[Common Application Proxy Settings](/connect/apps)
{% endcontent-ref %}


# Public Proxies

Public proxy servers maintained by the Anyone team allow users and services to route traffic through externally hosted SOCKS5 endpoints.

These proxies can be used to connect to the network from environments where running the client locally is not possible, or when a simple proxy connection is preferred.

Each proxy exposes a SOCKS5 interface that can be used by applications, operating systems, browsers, or backend services.

### **Available Proxies**

```
Nürnberg, Germany 
IP: 157.90.113.23
Port: 9052
```

```
Warsaw, Poland
IP: 57.128.249.250
Port: 9052
```

```
Oregon, USA
IP: 5.78.181.0
Port: 9052
```

More proxies may be added over time.&#x20;

### **Connecting to a Proxy**

Most operating systems and applications support SOCKS5 proxies. Configure the proxy in your application or system settings using the values provided above.

Replace the IP address with the proxy you want to use and once configured, compatible applications will route traffic through the selected proxy.

***Example using Telegram:***

<div><figure><img src="/files/cpHtlyfbc7xauAbVHmqM" alt="" width="225"><figcaption></figcaption></figure> <figure><img src="/files/khog47XTzppIau0FutBh" alt="" width="225"><figcaption></figcaption></figure></div>


# Linux

Linux users can run the Anyone (“Anon”) client directly on the machine, configuring it to route traffic or act as a proxy.

### Installation

First of all, install the package using [APT](/relay/start/install-anon-on-linux/apt) or any of the other available [sources](/relay/start/install-anon-on-linux#debian-and-ubuntu).

***

### Linux Proxy Settings

...


# MacOS

## Anyone Browser

Anonymous Onion Routing\
The v1 Anyone Browser is out with completely free, super-fast onion routing.

### Download from the App Store..

{% embed url="<https://apps.apple.com/gb/app/anyone-browser/id6741429520>" %}

Anyone Browser is supported on both MacOS and iOS.\
Read more about it in the [iOS section](/connect/ios#ios) of the docs.

<div><figure><img src="/files/b5AWJU5WVndoBzHPjGTi" alt=""><figcaption></figcaption></figure> <figure><img src="/files/Q8vw0tjzuA16zYAKMpo4" alt=""><figcaption></figcaption></figure> <figure><img src="/files/IhockqxquXktncirGTBh" alt=""><figcaption></figcaption></figure> <figure><img src="/files/F3z39qatAKXIniOv0Xqn" alt=""><figcaption></figcaption></figure> <figure><img src="/files/2aUHVxpB2wGK4W7vVT2q" alt=""><figcaption></figcaption></figure> <figure><img src="/files/Vuj30IRBnM5bE6wwYZnh" alt=""><figcaption></figcaption></figure></div>

***

## macOS with NPM

This guide will explain how to use the start the anyone-client and setup macOS to automatically route all compatible apps through the network, including browsers, streaming and more. We can do this using the Anyone SDK, which is built for creating private applications, but also works for individual use!

{% hint style="info" %}
**Primer: Test if you are on Anyone**

You can visit the URL <https://check.en.anyone.tech> to check that you aren't already connected to the Anyone network a different way
{% endhint %}

#### Install the Anyone Client

The simplest way to install anyone is through *npm.* If you already have npm, you can skip the collapsible window below

<details>

<summary>Installing npm</summary>

You can install easily by following the macOS guide on the [Node.js ](https://nodejs.org/en/download/package-manager)website. The steps are replicated here, to be pasted and run on the **Terminal** app on your Mac.&#x20;

1. Install nvm&#x20;

```
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.0/install.sh | bash
```

2. Use nvm to install Node.js 20

```
nvm install 20
```

3. Verify that you have installed Node.js and npm by ensuring you get a version code for each of these commands

```
node -v
npm -v
```

</details>

Once you have npm, simply install like below from the Terminal app

```
npm install @anyone-protocol/anyone-client 
```

#### Running the Client

&#x20;Once installed, you can start the anyone-client with the default configuration from the Terminal:

```
npx anyone-client
```

This will show a few setup messages, ending with&#x20;

<details>

<summary>Optional: Changing from the default configuration</summary>

If you have a specific use-case, or have issues with connecting in the subsequent steps, you can set&#x20;

`-s` Set the SocksPort (default: 9050)

`-c` Set the ControlPort (default: 9051, use 0 to disable)

`-o` Set the OrPort (default: 9001)

`-v` Enable verbose mode for full client logs

`-f` Set the path to custom anonrc config file

`-b` Set the path to custom anon binary (To use preinstalled one)

</details>

#### Routing System-Wide

To route system-wide, go to **System Preferences** and navigate to the **Proxies** window - the simplest way is to search for it from the searchbar. This will open a pop-up like below:

<div align="left"><figure><img src="/files/C829NmheF8eysSCTh2Zs" alt="" width="323"><figcaption></figcaption></figure> <figure><img src="/files/y1D0NJRkR3uckCv13vjv" alt="" width="563"><figcaption></figcaption></figure></div>

From there, enable the **Socks proxy** option and put in the following options:

```
Server: 127.0.0.1
Port: 9050
```

<div data-full-width="false"><figure><img src="/files/l3fCAdhYMgssIFoEAGFK" alt=""><figcaption></figcaption></figure></div>

If you are not running anyone-client on your macOS machine (for example, running it on the hardware or another local server), the server IP will be different. Head to [Connect Through Hardware](/connect/hardware) to see more cases.

#### Completing the Check

Once the proxy server is enabled, you can return to <https://check.en.anyone.tech> from Chrome, Brave or Safari and see if your perceived IP has changed!

#### Connecting Individual Apps

If you'd instead like to connect individual apps, instead of configuring all applicable programs, see the link below!

{% content-ref url="/pages/vHAXx7Cw1XfV74uhD2dZ" %}
[Common Application Proxy Settings](/connect/apps)
{% endcontent-ref %}


# Windows

## Windows Anon Executable

Windows version of Anon is portable, you can install it by downloading `.zip` archive from the release assets section below and extracting files from it.

<https://github.com/anyone-protocol/ator-protocol/releases>

#### Start

1. Create `anonrc` file in the folder with extracted files.
2. Open PowerShell in directory with extracted files.
3. Start Anon by typing `./anon -f anonrc` in PowerShell.

#### Uninstall

To uninstall simply remove downloaded files.

***

### Proxy settings:

[Windows 10/11](#windows-10-11-proxy-settings)\
[Windows 7](#windows-7)

### Windows 10/11 Proxy Settings&#x20;

If desired, an end user can configure windows to route all system traffic via the ANON network using windows in-built proxy manager.<br>

Download and run the `anon.exe` from Github packages. Select the latest version, download the zip, unpack and start the application from a terminal with option parameters or by running the executable as is with default settings.

1. Navigate to the settings app and ensure your windows system is up to date and all critical updates have been installed

   <figure><img src="/files/7Jg9G8HexH1CqoGZ2XH3" alt=""><figcaption></figcaption></figure>
2. Navigate to the "Network and Internet" section of the settings app and select "Proxy"

<figure><img src="/files/k9ftRH4Iy7eNZKhCbWHv" alt=""><figcaption></figcaption></figure>

1. Toggle "Automatically detect settings" ON and then click "Set up"

<figure><img src="/files/d1gojsnxHopMFwPz2wHJ" alt=""><figcaption></figcaption></figure>

4. A new pop up window will appear, toggle "Use a proxy server" ON and then enter your hardware configured socks 5 proxy settings (or any other configured ANON socks 5 proxy) in the following manner:

   1. Proxy IP address: socks=0.0.0.0
   2. Port: 9050

Substitute 0.0.0.0 for the socks5 proxy server IP and 9050 for the defined port, both can be configured in the anonrc file. Below is an example using a local machine:

<figure><img src="/files/ZQsFF69J4rTV985keLaf" alt=""><figcaption></figcaption></figure>

Toggle the "Don't use the proxy server for local (intranet) addresses option to ensure you will still be able to find local network devices when connected (i.e. network printers)

Click "Save" and now your windows device will no always route all its traffic via the configured ANON proxy provided the server is reachable - you can toggle the "Use a proxy server" ON and OFF as required and windows will keep the last used configuration information saved

***

### Windows 7

We do not advise using Windows 7 due to the product being EOL as of January 2020. Using an outdated OS can leave users vulnerable online.

1. Navigate to Control Panel > Network and Sharing Centre and click on "Internet Options" in the lower left hand corner

<figure><img src="/files/hI73CDDjxw9pP5qu6jux" alt=""><figcaption></figcaption></figure>

2. A new pop up called "Internet Properties" will open. On the navigation bar, select "Connections" and then "Lan Settings"

<figure><img src="/files/zhakzeQtBjv8MPLGTrJ7" alt=""><figcaption></figcaption></figure>

3. A new pop up called "Local Area Network (LAN) Settings" will open. Toggle ON the following 3 options and then click "Advanced"

<figure><img src="/files/VV34xyH1Ex19JIAashID" alt=""><figcaption></figcaption></figure>

4. A new popup called "Proxy Settings" will open. Ensure that all protocols are clear of any values (HTTP, Secure, FTP) and leave the option blank to use the same proxy server for all protocols. Only enter the socks5 proxy settings for your ANON server in the Socks section, including the relevant port. Both settings are configured in the anonrc file, or on your hardware relay's dashboard

<figure><img src="/files/njUSOHVXv001NIaDZLg8" alt=""><figcaption></figcaption></figure>

Click OK to save the settings and continue to click OK to close any additional tabs.&#x20;

To toggle the proxy off, navigate back to the settings page in step 3. and simple untick the "Use a proxy server for your LAN..." option

You windows machine will now route all traffic via the defined proxy server provided it is online and reachable&#x20;


# Android

Development in progress for Android; stay tuned!

{% embed url="<https://github.com/anyone-protocol/anon-android>" %}

<div align="left"><figure><img src="/files/0uOtJbonSzPAUy50EEwo" alt="" width="375"><figcaption></figcaption></figure></div>


# iOS

### Anyone Browser

Anonymous Onion Routing\
The v1 Anyone Browser is out with completely free, super-fast onion routing.

## Download from the App Store..

{% embed url="<https://apps.apple.com/gb/app/anyone-browser/id6741429520>" %}

***

<div><figure><img src="/files/2LmqAYGmdyy6emliyWGU" alt="" width="188"><figcaption></figcaption></figure> <figure><img src="/files/unfp8EdLKHLLXR8moEVH" alt="" width="188"><figcaption></figcaption></figure> <figure><img src="/files/Hk5J3hSm91Kg2U1ICjdp" alt="" width="188"><figcaption></figcaption></figure> <figure><img src="/files/kTj2aY1SmaUeUZgi5ae7" alt="" width="188"><figcaption></figcaption></figure> <figure><img src="/files/HYWAtJoDJRhMMW6vgwZv" alt="" width="188"><figcaption></figcaption></figure> <figure><img src="/files/dg7d6Ftiiy1B1MIPNj5c" alt="" width="188"><figcaption></figcaption></figure></div>

#### Complete anonymity at your fingertips

Anyone Browser is the free, open-source iOS browser that puts anonymity first. Powered by the decentralized Anyone Network, every connection routes through a global onion routing network, creating built-in anonymity more secure than any VPN, while remaining easy to use.

#### Secure Onion Routing

Every user gets free access to routing over the Anyone Network. This isn’t a VPN add-on: this is trustless anonymity done right. Your traffic passes through a series of three encrypted hops run by node operators around the world. No single server knows both who you are and where you’re going; see your three-hop 'circuit' for every page you visit!

#### No Tracking, No Logging, Anywhere.

Traffic never touches centralized servers. Your ISP, Wi-Fi router, or even the websites you visit can’t track you. The browser stores no history, and tabs can auto-delete all history every time you exit the app. You also get built-in protections against trackers:

* Script and cookie blocking
* Device fingerprint masking: hide your OS and default settings
* System obfuscation: masquerade as a different device altogether!

#### Fast, Private Browsing

Unlike older onion networks, the Anyone Network is built for speed. It’s noticeably less congested, meaning you can stream video, browse media-heavy sites, and get stuff done.

#### Privacy, Your Way

Take control with detailed privacy settings. Choose between Bronze, Silver, and Gold privacy levels, or customize every setting individually. Configure everything from:

* Your search engine
* Local protection with Face ID,
* Auto-delete tabs and more

Whether you care about data collection, surveillance, fingerprinting, or just want a browser that respects you, this is the complete privacy solution for iOS browsing.


# Hardware connectivity

Apps and users connect to the **Anyone Network** by running the **Anon Client**.

Most of the **Connect** section guides you through running the client on your computer, but you can also run it directly from your **Anyone Router hardware**! Here’s how:

### Topology of a typical home router setup

A home router usually sits at the center of the network, connecting to the **Internet Service Provider’s (ISP) modem** via the **WAN (Wide Area Network) port**. From there, the router provides connectivity to devices inside the home through two main paths; Wired LAN and Wireless LAN (Wi-Fi).

### **Anyone Router Feature**

The **Routing** feature allows operators to configure their device to route all hotspot traffic through the **Anyone Network**. This ensures that clients connecting to the hotspot have their traffic securely routed, enhancing **privacy and security**.

The Anyone device is placed between your home router (or directly replacing part of its functionality) and your client devices (phones, laptops, IoT, etc.).

Devices in your home connect via Wi-Fi to the Anyone device’s hotspot. The hardware intercepts all the traffic from these clients and forces it through the Anyone network

<figure><img src="/files/fLZzude3KiPOBP0hLyCl" alt=""><figcaption></figcaption></figure>

This feature is implemented using **iptables** rules to redirect traffic.

* **DNS traffic (port 53)** is redirected to **DNSPort 5353** to ensure proper name resolution.
* **All other traffic** is redirected to **TransPort 9055**, except for **DHCP requests**.

**Example commands used for routing:**

```bash
/usr/sbin/iptables -t nat -A PREROUTING -i wlan0 -p udp --dport 53 -j REDIRECT --to-ports 5353
/usr/sbin/iptables -t nat -A PREROUTING -i wlan0 -p tcp --dport 53 -j REDIRECT --to-ports 5353
/usr/sbin/iptables -t nat -A PREROUTING ! -d 10.42.0.1/32 -i wlan0 -p udp ! --dport 67 -j REDIRECT --to-ports 9055
/usr/sbin/iptables -t nat -A PREROUTING ! -d 10.42.0.1/32 -i wlan0 -p tcp ! --dport 67 -j REDIRECT --to-ports 9055
```

These rules ensure that all client traffic is automatically routed through the designated network.

***

{% hint style="success" %}

#### **How to Enable or Disable the Routing Feature**

1. Run the **wizard** once to activate it, see [Router Mode Setup](/hardware/setup-guides/router-mode) or [Setup Guide](/hardware/setup-guides/relay-mode)
2. To toggle the feature, simply turn the **hotspot OFF or ON** in [**Network Settings**](/hardware/setup-guides/controlpanel#network-settings).
   {% endhint %}

<figure><img src="/files/snU6XFVCwu3maqDDxzny" alt=""><figcaption></figcaption></figure>

***

### Anyone Proxy Beta&#x20;

<figure><img src="/files/t36nSrVsG91GNw9IFxea" alt=""><figcaption></figcaption></figure>

To enable a proxy server on the **LAN interface** for **Ethernet** or **WiFi**, toggle the sliders to enable or disable the proxy on the desired network interface. The interface must be connected for the proxy server to be available for clients to connect.

The Relay will set up a proxy server on **port 9050** and apply the necessary policies to restrict connections to clients within the same network.

{% hint style="info" %}
To learn how to Connect to the Proxy, see the "[Connecting to the Network](/connect/apps)" page for a detailed guide on some common applications.
{% endhint %}


# Common Application Proxy Settings

This page provides instructions on how to connect various applications and devices to the Anyone network using the SOCKS5 proxy protocol.

By [configuring your client settings](/relay/network/socks), you can ensure that your internet traffic is routed through the **Anyone** network, enhancing your privacy and security.

When a device connects as a client, its traffic is encrypted and directed through a series of relay nodes, similar to the SOCKS proxy configuration. Each relay node only knows the previous and next hop, keeping the full route concealed. This process safeguards your data from end-to-end, ensuring that both your identity and browsing activity remain anonymous.

### To set up a client connection

1. **Configure Proxy Settings**
   * Input the necessary proxy details (e.g., IP address, port) in your device or application settings as [configured](/relay/network/socks#edit-the-anon-configuration) or seen in the [Anyone Relay Control Panel](/hardware/setup-guides/controlpanel#proxy-settings-beta). This configuration ensures that your device can route traffic correctly through the network.
2. **Establish the Connection**
   * After entering the configuration details, connect your device. The **Anyone** network will handle the rest, encrypting your traffic and routing it through multiple layers to protect your anonymity.

The Proxy feature is your initial gateway to secure, anonymous browsing, streaming, downloading or various activities through the network. By following these simple steps, you can ensure that your online activities remain private and secure while additional connection methods are being developed.

### Configure a proxy connection

Different applications have unique settings for configuring a SOCKS5 proxy, but the general principles remain the same. Below are a few examples.

### Web Browsers

{% tabs %}
{% tab title="Firefox" %}
Anonymize and encrypt your web browsing.

1. Go to **Settings** > **General** > **Network Settings** > **Settings** and select **Manual proxy configuration**.
2. &#x20;Enter **SOCKS Host** (e.g., 192.168.1.10 or 10.42.0.1) and **Port** (9050).
3. Under "**SOCKS Host**" select "**SOCKS v5**" and check the box that says "**Proxy DNS when using SOCKS v5**".

<figure><img src="/files/Im7SWWYnHz5djR5Avwxq" alt=""><figcaption><p>Firefox Connection Settings</p></figcaption></figure>

{% hint style="info" %}
Exclude private networks, hostnames and addresses as needed under "No proxy for"
{% endhint %}

{% hint style="success" %}
A Proof-of-Concept script for easy setup was created for **Firefox** on **Windows**: check it out at:

<https://github.com/cl0ten/anon-launcher>
{% endhint %}
{% endtab %}

{% tab title="Chromium / Google Chrome / Brave / Edge" %}

<figure><img src="/files/0uOtJbonSzPAUy50EEwo" alt="" width="375"><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

### Messaging

{% tabs %}
{% tab title="Telegram Desktop" %}
Anonymize and encrypt your communications.

1. Go to **Settings** > **Advanced** > **Connection type**.
2. Select **Use Custom Proxy.**
3. Enter **Socket Address Hostname** (e.g., 192.168.1.10 or 10.42.0.1) and **Port** (9050).

<div><figure><img src="/files/yiz6n8XsInAzC0PaLN0q" alt=""><figcaption><p>Proxy Settings</p></figcaption></figure> <figure><img src="/files/q3LEBtFRIbdiwzdPqQGC" alt=""><figcaption><p>Edit Proxy</p></figcaption></figure></div>
{% endtab %}
{% endtabs %}

### File Transfer and Networking

{% tabs %}
{% tab title="FileZilla" %}
Anonymize and encrypt your downloads.

1. Go to Edit > Settings > Connection > FTP > Generic proxy
2. Select **SOCKS 5**.
3. Enter **Proxy Host** (e.g., 192.168.1.10 or 10.42.0.1) and **Proxy Port** (9050).&#x20;

<figure><img src="/files/nGz7UBP64lFDo1SPYqGS" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="qBittorrent" %}
Anonymize and encrypt your downloads.

1. Go to Tools > Options > Connections
2. Set Proxy Server Type to SOCKS5
3. Enter **Host** (e.g., 192.168.1.10 or 10.42.0.1) and **Port** (9050).

<figure><img src="/files/WcB9s4obb4GHcasgneqf" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

### Other

{% tabs %}
{% tab title="Spotify" %}
Anonymize and encrypt your streaming activity.

1. Go to **Edit** > **Preferences** > **Proxy Settings.**
2. Enter **Host** (e.g., 192.168.1.10 or 10.42.0.1) and **Port** (9050).&#x20;
3. **Restart App** to save the changes.

<figure><img src="/files/suqJxXTi9EQMCT9V2YvG" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Scripts

Linux users can run the Anyone (“Anon”) client directly on the machine, configuring it to route traffic or act as a proxy. Here are are few early proxy scripts that helps with the configuration.

{% content-ref url="/pages/iz3GY84GvnXx95wdhLSK" %}
[One-click Linux Proxy](/connect/scripts/linux)
{% endcontent-ref %}

{% content-ref url="/pages/ycVrstItyvlMZDyxRkym" %}
[One-click macOS Proxy](/connect/scripts/macos)
{% endcontent-ref %}

{% content-ref url="/pages/2VU9ATQ9bjVMn3xaKaRQ" %}
[One-click Windows Proxy](/connect/scripts/windows)
{% endcontent-ref %}


# One-click Linux Proxy

**Run this command to instantly start a proxy server and enable it for Linux. This will run the client and also auto-configure it for compatible traffic through WiFi. For Ethernet, check your OS settings.**

```bash
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/anyone-protocol/anon-install/main/linux/start_proxy.sh)"
```

Press '**Cmd+C**' to Cancel and disable proxy.

***

### Read Me

This command runs a script that downloads a executable Anyone client from [GitHub](https://github.com/anyone-protocol/ator-protocol/releases/) and executes the client with the configuration below:

```
SocksPort 127.0.0.1:9050
SocksPolicy accept 127.0.0.1
SocksPolicy reject *
HTTPTunnelPort auto
```

The script automatically configures proxy settings on the Wi-Fi interface and enables the proxy.

```bash
gsettings set org.gnome.system.proxy mode 'manual'
gsettings set org.gnome.system.proxy.http host '127.0.0.1'
gsettings set org.gnome.system.proxy.http port 9058
```

The script disables the proxy when '**Cmd+C**' is initiated.

```bash
gsettings set org.gnome.system.proxy mode 'auto'
gsettings reset org.gnome.system.proxy.http host
gsettings reset org.gnome.system.proxy.http port
```


# One-click macOS Proxy

This page provides instructions on how to quickly enable Anyone proxy for macOS, automating the steps in the previous guide into one command.

#### Run this command to instantly start a proxy server and enable it for macOS (on WiFi).&#x20;

{% code overflow="wrap" %}

```bash
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/anyone-protocol/anon-install/main/macos/start_proxy.sh)"
```

{% endcode %}

Press '**control+C**' to quit and disable proxy.

***

### Read Me

This command runs a script that downloads a executable Anyone client from [GitHub](https://github.com/anyone-protocol/ator-protocol/releases/) and executes the client with the configuration below:

```
SocksPort 127.0.0.1:9050
SocksPolicy accept 127.0.0.1
SocksPolicy reject *
HTTPTunnelPort auto
```

The script automatically configures proxy settings on the Wi-Fi interface and enables the proxy.

```bash
networksetup -setsocksfirewallproxy "Wi-Fi" 127.0.0.1 9050
networksetup -setsocksfirewallproxystate "Wi-Fi" on
```

The script disables the proxy when '**control+C**' is initiated.

```bash
networksetup -setsocksfirewallproxystate "Wi-Fi" off
```




---

[Next Page](/llms-full.txt/1)

