Smart import
vless/vmess/trojan/ss links, base64, JSON panels, full raw Xray and sing-box configs, AmneziaWG .conf and QR, olcRTC URIs, Happ profiles, bulk import from a list.
YPtun 3.5.5 is out · September 17, 2026 What's new ↗
Most clients give you one core and one way to connect. YPtun gives you a toolbox: Xray and sing-box, obfuscated AmneziaWG, Hysteria2 over QUIC, a tunnel through real calls and a DNS tunnel.
Apps hand packets to TUN, TUN passes them to the engine over a local SOCKS5, the engine sends them out. Both IPv4 and IPv6 are captured: nothing goes around the tunnel.
One tap and the client checks the nodes in your subscription. One does not answer, another is slow. It connects to the fastest live node and falls through to the next on failure.
If the node drops, auto-pick goes through the rest. If a whole protocol gets blocked, the same app has seven more engines.
auto-pick
For Russia, Iran and any country where sites vanish without warning. When one route stops working, what matters is not trying again — it is having the next one already set up.
Everything that matters sits on one screen: the button, the timer and the server list with pings.
Not a picture — tap Auto or the big button.
The big button in the middle connects to the selected server. Above it — how long the connection has held.
The round button next to it checks each server in your subscription. Which one is silent, which one is slow — right in the list.
The client takes the fastest live node. If it fails, it moves on to the next one by itself.
Download and upload in real time under the selected server. The same line can sit in the notification shade.
Import by QR, link or file, routing in a couple of toggles, split tunneling — and nothing extra.
Connect, auto-pick and subscription servers with pings.
QR code, link, file or free servers — dead ones are filtered out.
Bypass LAN and Russia, block ads. Custom rules and Happ profiles are one tab over.
Chosen apps go around the VPN. Russian ones with a single toggle.
Traffic, connection mode, subscriptions, a log for diagnostics.
Every core is built into a single gomobile library, so they share one process without conflicts. The core is picked per transport, automatically or by hand.
Classic proxy cores: VLESS+Reality, XHTTP, WS+TLS and the rest. The core is chosen for the transport automatically.
WireGuard with obfuscation: the handshake and packets do not look like plain WireGuard, which is often cut by signature.
A fast QUIC-based protocol with Salamander obfuscation and port hopping; holds its speed on unstable links.
Brings up a local WireGuard and pushes it through the TURN servers of VK calls; several "calls" are bonded for bandwidth.
A tunnel over DNS queries with its own ARQ transport and several resolvers — works where only DNS is open.
Video-call disguise: traffic goes through real conferencing services, so to DPI it looks like a live call.
A TCP tunnel to your own exit node through Yandex Docs or a MAX call — for when everything else is blocked. The node installs on a VPS in one tap.
A standalone background proxy for Telegram on top of Cloudflare WARP, independent of your main connection.
Switch on blocks the way a censor would and watch which paths survive. A regular VPN gives up at the first one. YPtun does not.
All paths are open.
The regular VPN is cut off.
vless/vmess/trojan/ss links, base64, JSON panels, full raw Xray and sing-box configs, AmneziaWG .conf and QR, olcRTC URIs, Happ profiles, bulk import from a list.
Happ-compatible profiles: block, direct and proxy by geoip, geosite, asn, domains and CIDR. Custom DNS and fakedns, a toggle for blocking RU domains.
Auto-refresh you can disable per entry, a live server counter, traffic and remaining quota, groups with collapse, pinning and ping sorting.
The app installs the server side of olcRTC, VK-TURN, freeturn, MasterDNS or OpenFlux on your VPS over SSH and verifies it by sha256.
Only the difference between versions is downloaded — a few megabytes instead of the whole build, on phone and desktop.
TLS fragmentation, multiplexing, AmneziaWG obfuscation and QUIC blocking where it leaks.
Captures both IPv4 and IPv6. FakeDNS no longer slips past the tunnel, and its table survives a reconnect.
Status, connection, server switching, "My IP" and settings straight from the tray. A global shortcut toggles the VPN from any application.
The same engines and the same interface on a phone, a laptop and a desktop. Routing settings move over with one yptun://routing link.
Android 6.0 and newer. Signed APKs for arm64, armv7 and x86_64 plus a universal build. In-app updates download only a patch.
Windows 10 and newer, x64 and native ARM64. Installer or portable .exe, signed via SignPath. Tunnel and Proxy modes, tray, global hotkey.
A .deb package for x64 and ARM64 — the same app and the same engines as on Windows.
The iPhone version is in beta and is not in releases yet.
The code is open under GPL-3.0, builds are made in GitHub Actions from this very repository, the Windows version is signed.
Permissions and signing in detail +The camera is only for the QR scanner, frames are processed on the phone. The battery exemption is only granted from a button in settings. Every permission is explained in the README.
Besides your servers, the app talks only to GitHub — for updates and routing lists — and to the services of the connection method you chose. It sends the check.happ-proxy.com mark only if a Happ subscription asks for it.
The Windows installer and portable build are signed with a SignPath Foundation certificate and built in GitHub Actions from open code.