TarnVPN

Verified safeOpen sourceExclusive
No reviews reviews
67
downloads
6.0
android

AI summary

VPN client for advanced users supporting VLESS, REALITY, XHTTP, and the full sing-box protocol stack. Forked from SFA with custom lx-layer transport pool and TLS fragmentation. No built-in servers—bring your own subscription or config. Interface in Russian and English. Notable permissions include CAMERA, WRITE_EXTERNAL_STORAGE, and QUERY_ALL_PACKAGES, which exceed typical VPN needs.

Generated by AI. May contain inaccuracies.

About this app

Android VPN Client for Blocked Networks: VLESS + REALITY, XHTTP, and the Full sing-box Protocol Stack — but with an Interface Built for the Task, Not a Config Editor

Here's who did what. The wrapper, share-link importer, and client-side customizations — that's this project. Everything it stands on belongs to others:

- The app is a fork of SagerNet/sing-box-for-android (SFA); - The core is sing-box, both by nekohasekai / SagerNet; - The lx layer — XHTTP, AmneziaWG 2.0, MASQUE, observability extensions — is Leadaxe's work, not ours. XHTTP is the transport this app leans on most heavily, and it's here thanks to that project.

Our own core modifications (the XHTTP transport pool backported to lx.15, TLS fragmentation over REALITY, override_destination for the sniff action, and the stream-one path) live in the downstream fork Amesu-afk/sing-box-lx — which is where the embedded libbox.aar is built from.

None of the projects mentioned support this app or are affiliated with it.

Let's get this out of the way first: there are no built-in servers

This is a client, not a service. You need your own server or subscription — the app only connects to what you give it. There are no embedded servers, no accounts, no payments, and it sends nothing anywhere except to your server (the sole exception is GitHub update checks, which can be disabled).

The interface is in Russian and English, following the system language.

Features

Servers

- A server is a list entry, not a config file. The "+" button accepts both a single link and a subscription URL. Supports vless, trojan, ss, vmess, hysteria2, tuic, anytls. Each server from a subscription becomes a separate entry, rather than being collapsed into one line. - Ping is visible before connecting. Measured via TCP handshake to the endpoint outside the tunnel, so numbers are available even when VPN is off. This is precisely why they won't match what urltest inside the core would show — they're different measurements. - Search, grouping by country ("Recommended" / "All Countries"), favorites, deletion along with the config file, and a "Connect to fastest server" button using already-measured pings. - Two honest status labels in the list, instead of silent failure: "Settings not applied — remove and re-add" (the profile was created with an older build; toggles won't affect it) and "Server certificate is not verified" (the link contained allowInsecure).

Subscriptions

A separate screen: updating calculates the difference by link (without #fragment, so renaming a server doesn't create duplicates), preserves your active server selection, and removes duplicates.

Protection

Main Settings

- Setting: Block VPN bypass What it does: Prevents apps from going outside the active tunnel. This is not a full kill switch: it works while the service is alive. To prevent traffic leaks if the service crashes or after reboot, you need the system "Always-on VPN" + "Block connections without VPN" — there's a link to these Android settings right in the "Lab" section.

- Setting: DNS protection What it does: All DNS queries go to your DoH resolver instead of the system one.

- Setting: Auto-connect What it does: Brings up the VPN when the app launches.

- Setting: DNS resolver What it does: Cloudflare, Google, Quad9, AdGuard, or your own IPv4 DoH address. The resolver is set by address, not by name, so no unencrypted "where is the resolver" query is needed before connecting. Changing the resolver rewrites all already-saved profiles, not just new ones.

Network

- Setting: DNS over VPN What it does: On — DNS goes through the tunnel; DNS-leak tests show the server's region, but cold queries pay a full round-trip. Off — fast direct DNS (still encrypted), but your real region is visible. Requests to media CDNs (googlevideo, cdninstagram, fbcdn, tiktokcdn, ttvnw, nflxvideo) are deliberately routed outside the tunnel: short-video feeds serve a new host for every clip, and through the tunnel each clip would start with a DNS wait.

- Setting: IPv6 What it does: Whether to route IPv6 traffic into the tunnel. The tunnel itself always captures IPv6 — otherwise a phone with native IPv6 would bypass the VPN entirely; the toggle decides whether IPv6 is used for routing decisions.

- Setting: TLS fragmentation What it does: Splits the TLS handshake — against DPI that looks at packet shape rather than SNI. A niche setting, off by default.

Split tunneling — app selection in "Only selected" / "All except selected" modes. Appearance: system, light, or dark theme.

Connection Lab

A screen for "it's not working, need to figure out what's wrong." The rule is simple: change one parameter at a time on the same network.

- QUIC policy — automatic (block so apps fall back to TCP, which goes cleanly through the tunnel), allow, or block explicitly. - Tunnel MTU, IP strategy (IPv4 only / prefer IPv4 / prefer IPv6), Secured DNS route (automatic / direct / over VPN), Log level. - Send hostname to server — like in Xray and v2rayNG: the server resolves the name and selects the region itself. This is what Gemini needs to avoid responding "not available in your region." YouTube is an exception — it's resolved by the phone, otherwise Music gets region-blocked. - Full active server test — a real HTTPS request through the already-established tunnel, with its own address, timeout, and retry count. - Recovery — restart VPN on Wi-Fi ↔ cellular handover, and offer a fallback server if the active one fails the test (switching only on your confirmation). - Open log — live core output at the selected level.

Debug log level writes visited domains and noticeably drains battery. Enable it while troubleshooting, then switch back to "Warnings."

License

Copyright © 2022 by nekohasekai

GNU General Public License v3.0

What's new

v1.14.0-alpha.48Aug 3, 2026

https://github.com/Amesu-afk/TarnVPN/compare/v1.14.0-alpha.47...v1.14.0-alpha.48/

About this version

Version
1.14.0-alpha.48 (700)
Size
100.48 MB
Requires Android
6.0
Target SDK
23
Architecture
x86, x86_64, arm64-v8a, armeabi-v7a
Downloads
67
Updated
Aug 3, 2026
Package
app.tarnvpn

Similar apps

Ratings & reviews

0 ratings
  • 5
    0
  • 4
    0
  • 3
    0
  • 2
    0
  • 1
    0

Write a review

Tap a star to rate this app