Operators running BTCPay Server through Docker deployments must now explicitly select Tor at their next setup or update to retain onion access. The change, introduced in version 2.4.5 released October 6, removes Tor from the automatically included components, converting a previously bundled service into an optional administrator configuration choice.
BTCPay announced the deployment change on October 5 alongside the version 2.4.5 release. For existing installations, the change takes effect at their next Docker setup or update.
Enabling Tor After Update
To restore Tor access after updating to version 2.4.5, administrators should run:
sudo btcpay-fragments add opt-add-tor
Existing Tor data remains preserved in current Tor volumes. The command reapplies setup and requires root access. Administrators can verify their configuration using btcpay-fragments show, which displays saved additional and excluded fragments without making changes.
BTCPay advises reviewing deployment changes before updating.
Private Services Require Exceptions
Version 2.4.5 also introduces a security change blocking outbound HTTP requests to private-network destinations by default for Lightning connections, LNURL requests, invoice notification URLs, and webhooks. This restriction aims to prevent server-side request forgery attacks.
Operators intentionally using private services must allow needed destinations through ssrfexceptions. After changing settings, administrators should restart the application and test affected integrations.


