TechEarl

Tor Bridges: obfs4, Snowflake, WebTunnel, and meek Setup

Get Tor bridges from official sources, use Tor Browser connection settings, and understand obfs4, Snowflake, WebTunnel and meek availability.

Ishan Karunaratne⏱️ 7 min readUpdated
Share thisCopied
Get Tor bridges from official sources, use Tor Browser connection settings, and understand obfs4, Snowflake, WebTunnel and meek availability.

To use a Tor bridge in Tor Browser, open Settings → Connection and choose a bridge under Bridges. Start with Connection Assist or a built-in transport offered by your version. If you need an obfs4 or WebTunnel bridge address, request one from Tor's official distribution channels and paste the full line into the browser.

A bridge is an entry relay omitted from Tor's public relay list. A pluggable transport changes how the connection to that entry point appears on the network. Neither guarantees that a connection will work on every censored network or be undetectable.

Set up Tor bridges in Tor Browser

  1. Update Tor Browser from its official distribution channel.
  2. Open Settings → Connection. On first launch, use Configure Connection.
  3. Try Connection Assist, or select a built-in bridge such as Snowflake if it is offered.
  4. For an obfs4 or WebTunnel address you requested, choose the option to provide a bridge and paste the complete bridge line.
  5. Connect and wait for bootstrap to finish. If it fails, inspect the connection log before changing several settings at once.

Menu wording can vary by platform and release. The Tor Browser unblocking guide documents the current controls. Tor Browser includes transport support; installing a separate system Tor service is not necessary for this workflow.

obfs4 vs Snowflake vs WebTunnel vs meek

TransportConnection approachWhat you normally configure
obfs4Obfuscates the connection to a bridgeA complete obfs4 bridge line
SnowflakeConnects through volunteer proxies using WebRTCThe built-in Snowflake option in Tor Browser
WebTunnelWraps the bridge connection in HTTPS-like web trafficA complete WebTunnel bridge line
meekUses web-based tunnelling through supported infrastructureAn available built-in option or current official configuration

There is no universal speed ranking or guaranteed best transport. Availability depends on the network, the bridge, and the infrastructure a transport currently uses. If one fails, try another supported option; Tor publishes guidance for censored regions.

Snowflake's browser extension is for volunteers helping others connect. To use Snowflake as a client, select it in a Tor-powered application such as Tor Browser. The Snowflake project explains the distinction.

Where to get a Tor bridges list

Request addresses instead of copying a public list from an old blog post. Publicly reposted addresses may already be blocked. The official getting-bridges guide lists these methods:

  • Inside Tor Browser: request a bridge from the Connection settings.
  • Website: use bridges.torproject.org.
  • Telegram: follow the official guide's link to GetBridgesBot; it supports obfs4 and WebTunnel requests.
  • Email: request bridges from bridges@torproject.org using a supported sender. The guide lists Gmail and Riseup as of 21 September 2026.

Snowflake is not a static list of volunteer proxy IPs to paste into this field. Its connection configuration discovers proxies. Do not assume that a bridge email request can supply every transport type.

Configure a standalone Tor daemon

This section is for the tor service, not Tor Browser. The daemon needs a transport executable available to the service account. Tor's current standalone bridge instructions use Lyrebird, which implements several transports. Some distributions also package a separate obfs4proxy client.

Find the executable actually installed on your system:

bash
command -v lyrebird
command -v obfs4proxy

Use the path you found in ClientTransportPlugin. For an obfs4-only setup with Lyrebird installed at /usr/bin/lyrebird, the configuration starts like this:

text
UseBridges 1
ClientTransportPlugin obfs4 exec /usr/bin/lyrebird
# Add a complete Bridge obfs4 line obtained from an official source below.

This is a configuration skeleton, not a working bridge address. Add the complete issued line, including address, fingerprint, cert, and iat-mode. Do not use made-up certificates or documentation IP addresses. Keep private bridge lines out of public repositories.

For Snowflake or meek, copy the current full transport configuration from Tor's instructions, including broker/fronting parameters where required. A bare historical fingerprint or an old CDN endpoint is not a reliable working setup. Listing two transport types in torrc is not a documented “try this one first, then that one” priority policy.

Reload and verify one change at a time

For a Linux service using /etc/tor/torrc, check the configuration before reloading:

bash
tor --verify-config -f /etc/tor/torrc

Use the actual service account and configuration path if your package requires them. Stop if validation fails. Then reload the specific Tor service instance you configured; on Debian-style installations this may be tor@default, while other packages use tor.

bash
sudo systemctl reload tor@default
sudo journalctl -u tor@default -n 80 --no-pager

These service names are examples, not commands to run against every Tor process. Wait for Bootstrapped 100% and test a request through that instance's SOCKS proxy. Tor Browser has its own connection log and does not necessarily share the system service's configuration.

If a Tor bridge will not connect

SymptomCheck next
Transport executable cannot startFile path, execute permissions, package installation, service logs
Bridge line rejectedMissing fields, accidental line breaks, wrong transport name
Bootstrap stallsClock, network access, bridge reachability, and the current region guidance
Works on another networkFiltering may differ; this alone does not identify the exact blocking mechanism
Tor Browser works but the daemon failsCompare the daemon's transport version and configuration; they are separate installations

Try a fresh bridge or a different transport when the current one fails. There is no need to rotate a working bridge on a made-up fixed schedule. Avoid publishing a private bridge while asking for help; redact its address and certificate from logs.

Running your own obfs4 bridge

Operating a bridge requires reachable ports, an appropriate bandwidth budget, and a correctly configured transport. Follow Tor's bridge operator instructions for the current packages and service setup. A short BridgeRelay 1 snippet alone does not cover firewall rules, privileged ports, or transport permissions.

FAQ

Not necessarily. Bridges are useful for blocked connections and some circumstances where you want to make Tor use less obvious to a local observer. They do not provide a universal invisibility guarantee.

Request them inside Tor Browser or through the Tor Project website, official Telegram bot, or supported email channel. Copy the full issued line and avoid republishing it.

In Tor Browser, select the built-in Snowflake option. The application supplies its transport configuration and discovers proxies. You do not need a public list of volunteer proxy addresses.

It selects an inter-arrival timing mode. Keep the value supplied with the bridge line; changing it is not a guaranteed way to defeat blocking.

Not by itself. A circuit change does not repair an unreachable entry bridge. Check the connection logs, request a fresh bridge, or try another supported transport.

See also

TagsTORBridgesobfs4SnowflakemeekPluggable TransportsCensorship CircumventionPrivacyAnonymity

Found this useful? Pass it on.

Copied

Ishan Karunaratne

Systems and Network Architect · Chief Technology Officer

Systems and network architect and Chief Technology Officer with more than two decades designing, building, and running production software, cloud and network architecture, Linux systems, and the bare metal underneath them, and lately working AI into the stack. A US Army veteran who served in Operation Iraqi Freedom. What I write here is drawn from the full arc of that work, across architecture, engineering, and operations, not any single job.

Keep reading

Related posts