Access guide · clearnet to Tor · 2026

How to Access WeTheNorth Safely in 2026: Clearnet to Onion, Step by Step

Reaching WeTheNorth is a short trip with two checkpoints. You start here, on the clearnet. You carry the signed onion across into Tor. Then a PGP check proves that address is the real market before you type a single thing. Skip the order and a look-alike page can grab your login on the first try. This guide walks the whole run.

Canon pointerRather than repeat the register here, this walkthrough sends you back to one source of truth. The address you copy and every mirror we sign live on the canon, checked against a single key.hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onion
The handofftwo checkpoints

The bridge from an open browser to a real WeTheNorth login

Almost every bad WeTheNorth login begins the same way. Someone jumps from a search box straight to the password field, forgetting that a darknet market login sits behind a signed address, not a bookmark — the same discipline a vendor's escrow reputation depends on applies just as much to the mirror you trust to get there. The safe route drops two checks into that gap. This is the shape before the steps.

Access handoff: you start on this clearnet page, take the verified onion across into Tor, and reach the WeTheNorth market only after the signature checks.Clearnetthis pageHandoffverify + carryOnionWTN market
Start on clearnetThis page lives on the open web so a search can find it. All it hands you is a checked address.
Carry and verifyYou move the onion into Tor and test it against the PGP signature, not against how convincing the page looks.
Reach the marketOnly an address that cleared the check gets your login, and only inside Tor Browser.
Step by stepfollow in order

Five steps to reach WeTheNorth without touching a clone

  1. Boot Tails, or set Tor Browser to Safest. With scripts off, a hostile mirror loses most of its tricks.
  2. Grab the canon PGP key before you glance at any address. That key is the yardstick for every link after it.
  3. Pull the signed register, run the signature check, and confirm the fingerprint is the one you already hold.
  4. Copy the onion off the verified box. Do not retype it, and do not trust a link from search, a forum, or a chat.
  5. Load it in Tor, clear the captcha, then log in. Keep this identity walled off from your real name.

The captcha before the login box is normal and slows bots. A page that skips it and asks for money up front is not WeTheNorth.

Key importstep two, up close

How do you import the WeTheNorth key and check a signature?

Step two is the one people skip, so here it is in full. You import the published key once. After that you use it to test the signature shipped next to the register. If the test passes, the list is genuine and the address inside it is safe to copy. If it fails, you stop right there.

gpg --import wethenorth-canon.asc
gpg --verify mirrors.json.sig mirrors.json

A pass reads as a good signature from the canon key. Then compare the printed fingerprint against the one you trusted the first time. New to this? Start on the signed canon, where the key and directory live.

Honest limit. We hand you the method, we cannot police your machine. A hijacked clipboard or a stale bookmark can still aim you at the wrong host, so run the check every time.

Why the official WeTheNorth key import only happens once

You do not re-import the key every session — you import the official canon key a single time, then reuse it to verify every future register update. Re-importing on every visit from a fresh copy defeats the purpose, since a compromised source could hand you a different key each time and you would never notice the substitution. Keep the key material somewhere you control, separate from wherever you found this page.

What a failed WeTheNorth signature check actually means

A failed verification means exactly one thing: the file you tested does not match what the official key signed, full stop. It does not mean "probably fine, try again" and it does not mean the WeTheNorth onion itself is compromised — it means the specific register copy in front of you is not trustworthy. Go back to a source you trust for the canon key and register, and start the check over from there rather than proceeding on a failed result.

TROUBLESHOOTINGcommon access failures

What to do when the WeTheNorth access sequence stalls

Most reported "WeTheNorth won't load" problems are Tor-layer issues, not WeTheNorth issues, and the fix rarely involves searching for a different link.

The circuit times out before the WeTheNorth page loads

Onion services are naturally slower than clearnet sites — three to six relay hops instead of one — so a WeTheNorth page that takes 10-20 seconds is normal, not broken. If it genuinely times out, request a new Tor circuit for the site rather than immediately assuming the WeTheNorth mirror is down; a fresh circuit through different relays resolves the majority of one-off timeouts.

The WeTheNorth page loads but looks visually broken

Tor Browser's Safest security level disables JavaScript and some rendering features by design, so a page missing animations or interactive elements is expected behavior, not a sign of a compromised or fake mirror. Judge a WeTheNorth mirror's authenticity by its onion address and PGP fingerprint, never by how polished the page looks with scripting disabled.

Everything on the signed list reads Dead

This is rare and worth taking seriously, but the correct response is still patience, not panic. Rebuild your Tor circuit, wait, and check back rather than searching a forum for an alternate link — that is exactly the moment a phishing campaign is most likely to be waiting with a convincing-looking clone.

DEVICE SETUPbefore the first connection

Getting the device right before you ever open WeTheNorth

The access sequence described above assumes Tor Browser is already installed correctly and the device it runs on is not quietly working against you. Two setup mistakes cause more failed WeTheNorth access attempts than anything about the onion address itself.

Download Tor Browser from the real source, not a search result

Tor Browser should come from the official Tor Project distribution, verified by its signature, not from a link in a forum post or a sponsored search result promising a faster or pre-configured version. A modified Tor Browser build is one of the most effective ways to compromise someone before they ever reach a WeTheNorth address, because every subsequent verification step in this guide assumes the browser itself is trustworthy.

A VPN in front of Tor changes your threat model, not just your speed

Running a VPN before Tor hides Tor usage from your ISP but adds the VPN provider as a party that can see you are connecting to Tor, and in some configurations can see timing patterns worth correlating. Whether that trade-off makes sense depends on what you are defending against — a local network operator versus a well-resourced adversary — and is worth deciding deliberately rather than defaulting to "VPN plus Tor is always safer."

Keep the WeTheNorth session separate from everything else

Opening WeTheNorth in the same browser profile used for ordinary browsing, or on a device logged into personal accounts, undermines much of what Tor provides. A dedicated Tails session, or at minimum a Tor Browser profile used for nothing else, keeps a WeTheNorth session from picking up fingerprinting signals tied to your everyday browsing habits.

Clock and locale settings can leak more than expected

An unusual system clock offset or a browser locale that does not match Tor Browser's default can, in principle, narrow the pool of users a connection could belong to. Tor Browser's defaults are deliberately uniform across users for this reason — resist the urge to customize timezone, language, or window size for a WeTheNorth session, since blending into the default profile is itself part of the protection.

TWO KINDS OF CHANGEbrowser update vs address rotation

What changes between a Tor Browser update and a WeTheNorth address rotation

Two unrelated kinds of change can both disrupt a WeTheNorth access attempt, and confusing one for the other leads to the wrong fix. Telling them apart takes one question: did the browser change, or did the address change.

A Tor Browser update changes the tool, not the destination

When Tor Browser updates, the interface, the bundled Tor client, and the default security settings can shift, but the WeTheNorth onion address you already verified does not change because of it. If access breaks right after an update, the fix is almost always re-checking your security-level setting or clearing a stale circuit — not searching for a new WeTheNorth link.

A WeTheNorth address rotation changes the destination, not the tool

WeTheNorth rotating its onion address — after planned maintenance, a suspected compromise, or routine key hygiene — is unrelated to whatever Tor Browser version you are running. The fix here is the opposite of the update case: your browser is fine, but the address you have saved is stale, and the correct response is re-verifying against the current signed record on this register rather than adjusting any browser setting.

Why conflating the two leads people toward unsafe fixes

Someone who assumes a broken WeTheNorth connection must mean their browser is outdated may go looking for a Tor Browser download outside the official channel, which is a meaningfully worse mistake than the original problem. Someone who assumes it must mean their old address rotated, when the real issue was a browser setting, may go searching forums for an alternate WeTheNorth link and land on a clone. Diagnosing which kind of change actually happened, before acting, avoids both failure modes.

Questionsplain answers

WeTheNorth access questions people actually ask

Do I need Tails, or is Tor Browser enough?

Tor Browser at the Safest level covers most people. Tails adds a system that forgets everything on shutdown, which is worth it if you want no local trace.

Why import the key before I look at a link?

Read the address first and you are tempted to trust it before you can test it. Holding the key first means every candidate gets judged, not just the ones that look off.

My address is a couple of characters off. Still usable?

No. One wrong character is a different server, which here usually means a clone. Discard it and copy a clean one from the register.

Deeper readingworked example + pitfalls

What to do when the sequence stalls, and how to avoid needing this

Worked example: recovering from a failed step three

Say step three — verifying the signed register — fails to confirm. Do not skip ahead and open an onion address anyway; a failed signature check at this point means don't proceed, not proceed carefully. Go back to the canon page directly, re-download the register and signature fresh, and re-run the check. Most stalls at this step come from a stale saved copy of the register rather than an actual compromise, but the fix is the same either way: pull fresh, verify again, and only move to the onion address once the signature and fingerprint both check out cleanly.

Common access mistakes, expanded

Typing a WeTheNorth address into a clearnet search bar. Search engines index clearnet content; a genuine onion address for WeTheNorth generally will not appear there the way a marketing site would, and results that do claim to be WeTheNorth are exactly the kind of unverified links this whole sequence is built to filter out.

Connecting before Tor Browser has finished establishing circuits. Opening an onion address the moment the browser launches, before it has fully bootstrapped, produces confusing errors that have nothing to do with WeTheNorth being down. Wait for a stable connection first.

Treating the five-step sequence as optional after the first successful visit. Each element — hardened browser, imported key, verified register, exact address copy, separate identity — addresses a different failure mode. Skipping steps because a previous session went fine reintroduces exactly the risk those steps were built to close.

Every step in this sequence exists to answer one question about one string: is this specific onion address the real WeTheNorth onion, reachable right now, over a Tor identity that is not shared with anything else. Hardening the browser protects the session once you reach that onion address. Importing the key and checking the register are what let you trust the onion address in the first place. The fifth step, a separate identity, protects you after you have connected, regardless of how the onion address was confirmed.

External resourcesthe software this run depends on

The software a safe WeTheNorth access run actually depends on

Every step in this guide runs on independently maintained software, not anything built by this WeTheNorth register. Reading their documentation directly is worth it before your first WeTheNorth session.

Keep readingrelated WeTheNorth pages

More WeTheNorth verification reading

Once the clearnet-to-Tor handoff above is done, the rest of a WeTheNorth session runs through pages covered elsewhere on this register: the full PGP verification walkthrough, the opsec baseline worth locking in before you connect, and the WeTheNorth login steps once the signature checks out. If you want live reachability first, the status grid shows the current probe state, and the about page explains what this register does and does not vouch for. The Electronic Frontier Foundation and Privacy Guides both publish independent guidance on the same clearnet-to-Tor handoff described above.

Related

Next moves

Holding a link and want to test it, or heading straight for sign in? Pick up the thread. The status page explains the probe states you will see.

Read the login notes