Every way through, in one app.
English · فارسی
ZedSecure is a VPN and proxy client for Android, Linux, Windows and macOS that ships with more than one engine. When one route is blocked, the next one is already installed: Xray and sing-box for the usual protocols, Psiphon and Tor for when nothing else connects, DNS tunnels for networks that let little more than DNS through, and WireGuard, AmneziaWG, OpenConnect and IKEv2 for servers you already run. Engines can be chained through each other, and one tap tests every server and moves the connection to the fastest one.
| Engine | Carries |
|---|---|
| Xray | VLESS with Reality, Vision and XHTTP, VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, AmneziaWG |
| sing-box | TUIC, Naive, AnyTLS, ShadowTLS, OpenVPN .ovpn files, and plain sing-box JSON |
| Psiphon | Psiphon's own network; no server of yours needed |
| Tor | obfs4, Snowflake and Conjure bridges |
| DNS tunnels | DNSTT, VayDNS and MasterDNS, over UDP, TCP, DoT or DoH |
| OpenConnect | Cisco AnyConnect and compatible gateways |
| IKEv2 | the IPsec client built into Android |
| SSH | on its own, or through any of the above |
Android has all of them. Linux, Windows and macOS carry Xray, sing-box, the DNS tunnels and SSH.
- Imports share links, subscriptions, Xray and sing-box JSON,
.ovpn, Amneziavpn://and QR codes - Auto-select keeps the tunnel on the fastest server and fails over on its own
- Chains in both directions, for example Xray over Tor or Tor over Xray
- Per-app routing, a geoip/geosite rule editor, and SNI spoofing on rooted devices
- Vault: share a config as a
.zsxfile that connects without showing it, with an optional password and expiry date - Speed test, MTU finder, DNS resolver scanner and a live log
- Material 3 Expressive, light and dark, in English, Persian, Russian and Chinese
Android: Google Play, or the
APK for your device from Releases
(arm64-v8a for almost every phone, armeabi-v7a for older ones).
Linux: .deb, .rpm, .AppImage or .tar.gz from Releases. On NixOS,
nix run github:CluvexStudio/ZedSecure.
Windows: the .msi installer, or the portable .zip.
macOS: the .dmg for Apple Silicon or for Intel. The app is not notarized, so open it the
first time with right-click, then Open.
./tools/fetch-cores.sh # every engine at its pinned commit
./tools/build-zedcore.sh # the Android core; needs Go 1.26.3 and NDK 28 or newer
./gradlew :app:assembleRelease # three APKs, one per ABI
./gradlew :desktop:packageDeb # or packageRpm, packageMsi, packageDmgThe engines we patched are published as forks; tools/core-sources.txt
lists each one with the exact commit a release is built from. Pushing a v* tag builds and signs
the Android release in CI, and a desktop-v* tag builds the desktop one.
The DNSTT and VayDNS modes of the DNS tunnel are built with the VayDNS library, a fork of dnstt. The MasterDNS mode is a separate engine, credited below.
The main ideas of the tunnel come from SlipNet by anonvector: DNS over plain TCP (VayDNS does not have this by itself), the fan-out and round-robin resolver modes with spread count, the DNS pool that picks the fastest resolvers on each connect, the global resolver override and prevent-DNS-fallback settings, and the design and text of the DNS and SSH settings.
Versions before 3.0.9 used SlipNet's own engine, including its TCP transport, inside the core. Since 3.0.9, the engine is zeddns, written for this app. It has the same features, but with its own code.
ZedSecure also stands on Xray-core, sing-box, Psiphon, Tor, MasterDnsVPN, AmneziaWG, OpenConnect, and hev-socks5-tunnel. Their licences are in NOTICE.
AGPL-3.0. The core also links sing-box, Psiphon and sing-openvpn, which are GPL-3.0; section 13 of GPL-3.0 allows combining them with AGPL-3.0 code, and each keeps its own licence.
