Arti adoption status at the end of 2024: client parity reached, relays still waiting
At the close of 2024, Tor's Rust rewrite quietly crossed a threshold its developers had chased for years. With Arti 1.3.0, the team declared parity on most major client features with the battle-tested C implementation.
The network-facing half of the rewrite tells a different story. Relays remain out of reach, and anyone operating clients, bridges, or onion services needs to know exactly where that line sits today.Client parity, finally
The Tor Project's 1.3.0 announcement on October 31 called it a significant milestone: Arti had achieved parity on most major client features with C Tor, including bridges, pluggable transports, and onion service access (blog.torproject.org/arti_1_3_0_released). Work on Arti Relay and the RPC subsystem was described as accelerating. The road there ran through a busy 1.2.x series. March's 1.2.0 release made running onion services non-experimental and patched a low-severity traffic-signaling bug tracked as TROVE-2024-001, while stating plainly that Arti onion services were not yet recommended for production or any purpose requiring privacy (https://blog.torproject.org/arti_1_2_0_released). By summer, vanguard protection against guard discovery had landed for onion service circuits.Embedded Tor is the whole point
Unlike the original C tor, which grew its integration features as bolt-ons, Arti was designed from the start as a modular, embeddable library. The arti-client crate exposes an async Rust API that lets applications open anonymized streams directly, and it has become a regular dependency in the Rust ecosystem. Mobile is the flagship use case. The Tor Project-supported arti-mobile library brings the Rust runtime to Android and iOS builds, replacing aging bundled C tor stacks in apps like Orbot (https://gitlab.com/guardianproject/tormobile/arti-mobile). For non-Rust languages, the practical integration path remains spawning the arti binary as a SOCKS proxy, because a stable FFI does not exist yet. That caveat matters for adopters. Arti's developers warn that lower-level APIs break frequently between releases, so embedding means committing to regular version bumps rather than fire-and-forget upgrades.A memory quota against denial of service
November brought the year's most operationally significant feature. Arti 1.3.0 introduced memory quota tracking, letting operators cap how much memory remote users can force an Arti process to consume (https://blog.torproject.org/arti_1_3_0_memquota). The threat is not hypothetical. Researchers showed back in 2014 that queued-data exhaustion can help deanonymize hidden services, and the new tracker implements the recommended countermeasure by tearing down the oldest connections first. It is also a prerequisite for the relay code now under development. One configuration detail trips people up: unlike C Tor's MaxMemInQueues, the limit is off by default and requires an explicit max setting in arti.toml. The developers flag the code as very new and ask early adopters to report what they find.Relays: scaffolding, not switches
Can you run an Arti relay at the end of 2024? No. The December 3 release of Arti 1.3.1 continued relay and RPC development and added initial scaffolding for service-side proof-of-work defenses (https://blog.torproject.org/arti_1_3_1_released). The project changelog shows placeholder relay backend sketches and reactor designs landing in the tor-proto crate, which is groundwork rather than shippable functionality (https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md). The official FAQ sets expectations honestly: C Tor will be maintained and supported until Arti is a viable replacement for the vast majority of use cases, a transition estimated to take several more years at minimum. Nobody should plan a relay migration on a 2025 calendar.Arti is designed from the ground up to work as a modular, embeddable library that other applications can use.
What client operators should prepare for
For anyone embedding or deploying Arti today, the practical checklist is short but specific.- Pin your arti-client version tightly and budget for semver-driven upgrade work every few months.
- Keep privacy-critical onion services on C Tor; Arti's own release notes still discourage production onion hosting.
- If you do host services on Arti, enable the memory quota explicitly and monitor reclamation logs.
- Watch the RPC subsystem: it is slated to replace C Tor's control-port integrations eventually.