WireGuard · OpenVPN · Proxy

VPN & proxy hosting with full root

Deploy WireGuard, OpenVPN, SoftEther, or commercial VPN and proxy stacks on offshore KVM VPS or dedicated hardware — crypto checkout, 500Gbps DDoS, and European jurisdiction options.

Privacy tools need kernel access, custom networking, and a host that does not treat VPN as a forbidden category by default. TheOnionHost sells SSD VPS and dedicated servers for operators who run personal tunnels, small multi-user VPN services, reverse proxies, and private network exits. You install the stack yourself; we provide the isolated machine, bandwidth, and mitigation.

Privacy tools are allowed under our Acceptable Use Policy. That includes VPN servers, proxies, and related encryption tooling used for legitimate privacy and remote access. What is not allowed is turning the server into phishing infrastructure, malware distribution, botnet C2, or DDoS-for-hire. Read the AUP section below before you scale a public product.

What you can deploy

Shared hosting cannot host these workloads. You need KVM root (or bare metal) so you can open ports, load modules, shape traffic, and run long-lived daemons without panel restrictions.

Recommended tiers

Start from the lightest plan that covers concurrent users and throughput. Upgrade RAM and cores when handshake load, logging, or multi-protocol frontends grow. Entry VPS starts at $19.99/mo.

Use case Typical needs Recommend From
Light / personal VPN Few devices, WireGuard or OpenVPN, modest bandwidth VPS Alpha or Proxima $19.99/mo
Small multi-user VPN Dozens of clients, dual protocols, basic panel VPS Ultra (4 GB / 4 vCPU) $40/mo
Growing multi-user / proxy farm Higher concurrency, more CPU for crypto, larger logs VPS Infinity or entry dedicated $50/mo VPS
Heavy / commercial scale Large concurrent sessions, IP pool planning, isolation Dedicated servers Dedicated pricing
Western EU peering preference AMS routes, Dutch jurisdiction option Netherlands servers See NL page

All listed VPS plans include full root, NVMe storage, unmetered bandwidth options, 1 Gbps port, and 500Gbps DDoS. Specs: Alpha 1 GB · Proxima 2 GB · Ultra 4 GB · Infinity 8 GB.

Full root access

Every VPS is KVM with true root. You choose the OS image, install WireGuard or OpenVPN from packages or source, configure firewalls (nftables/iptables), sysctl tuning, fail2ban, and your own monitoring. Dedicated servers add hardware isolation and IPMI-style out-of-band management for operators who need to reinstall without relying on a hypervisor panel alone.

Crypto billing, no KYC on standard orders

Pay with Bitcoin, Monero, Ethereum, USDT, Litecoin, and related options at checkout. Standard self-serve orders need an email only — we do not require government ID for ordinary VPS or dedicated purchases. Most instances provision automatically after payment confirms, so you can stand up a tunnel endpoint the same day.

Operational note: We do not operate your VPN brand for you. Logs, user databases, and abuse desks are your responsibility. Keep retention policies aligned with the law of the server jurisdiction and your own product promises.

Acceptable use — privacy tools yes, abuse no

Our Acceptable Use Policy explicitly supports privacy-oriented tooling: VPN, proxy, and similar services used for encryption and remote access. The same policy prohibits:

If a complaint concerns copyright-style notices from another country, we evaluate under local jurisdiction law only. Informational notices may be forwarded; unilateral removal based solely on a foreign instrument is not automatic. Details: jurisdiction & notice policy.

Locations and networking

VPS and dedicated inventory spans European locations including Bulgaria and Ukraine, with Netherlands options for operators who want AMS-connected dedicated capacity. Every plan includes 500Gbps DDoS mitigation. You still harden UDP/TCP listeners, rate-limit auth endpoints, and keep software patched — mitigation is not a substitute for secure VPN configuration.

Next steps

Choose a tier from the table, order VPS or dedicated, install WireGuard or OpenVPN, and lock down admin ports. Policy and product links: