Isn’t the hash ( before the . Onion) is the public key ?
So technically we don’t need a cert for onion
You're correct, but I recall a Tor dev saying at one point that HTTPS for .onion wasn't completely useless, I think in that more secure settings (CSP, etc.) apply to pages loaded with HTTPS.
Some onion websites use the certificate as an anti-phishing measure. Since onion domains are hard to remember, a certificate can verify that you are, indeed, connected to e.g. Facebook’s servers and not a phishing website.
Presumably worked a lot better when EV certs got the fancy UI