
Open-source VPN protocol that tunnels TCP, UDP, and ICMP traffic over HTTPS, bypassing DPI and throttling. Features split tunneling, SOCKS5 proxy, custom DNS, and cross-platform clients.
Clients · App store · Play store
TrustTunnel is a modern, open-source VPN protocol originally developed by AdGuard VPN and now available for anyone to use and audit.
It delivers fast, secure, and reliable VPN connections without the usual trade-offs. By design, TrustTunnel traffic is indistinguishable from regular HTTPS traffic, allowing it to bypass throttling and deep-packet inspection while maintaining strong privacy protections.
The TrustTunnel project includes the VPN endpoint (this repository), the library and CLI for the client, and the GUI application.
VPN Protocol: The library implements the VPN protocol compatible with HTTP/1.1, HTTP/2, and QUIC. By mimicking regular network traffic, it becomes impossible to detect and block.
Flexible Traffic Tunneling: TrustTunnel can tunnel TCP, UDP, and ICMP traffic to and from the client.
Platform Compatibility: The server is compatible with Linux and macOS. The client is available for Android, Apple, Windows, and Linux.
Traffic Tunneling: The library is capable of tunneling TCP, UDP, and ICMP traffic from the client to the endpoint and back.
Cross-Platform Support: It supports Linux, macOS, and Windows platforms, providing a consistent experience across different operating systems.
System-Wide Tunnel and SOCKS5 Proxy: It can be set up as a system-wide tunnel, utilizing a virtual network interface, as well as a SOCKS5 proxy.
Split Tunneling: The library supports split tunneling, allowing users to exclude connections to certain domains or hosts from routing through the VPN endpoint, or vice versa, only routing connections to specific domains or hosts through the endpoint based on an exclusion list.
Custom DNS Upstream: Users can specify a custom DNS upstream, which is used for DNS queries routed through the VPN endpoint.
An installation script is available that can be run with the following command:
curl -fsSL https://raw.githubusercontent.com/TrustTunnel/TrustTunnel/refs/heads/master/scripts/install.sh | sh -s -
The installation script will download the prebuilt package from the latest
GitHub release for the appropriate system architecture and unpack it to
/opt/trusttunnel. The output directory could be overridden by specifying
-o DIR flag at the end of the command above.
If you want to install a specific version (instead of the latest), use -V <version>:
curl -fsSL https://raw.githubusercontent.com/TrustTunnel/TrustTunnel/refs/heads/master/scripts/install.sh | sh -s - -V <version>
[!NOTE] Prebuilt packages are available for
linux-x86_64,linux-aarch64, andmacos-universal(Intel and Apple Silicon) architectures.
The installation script always installs the latest available version. So, to update your installation, run the install command again:
curl -fsSL https://raw.githubusercontent.com/TrustTunnel/TrustTunnel/refs/heads/master/scripts/install.sh | sh -s -
This re-runs the installer and replaces the binaries in the installation
directory (/opt/trusttunnel by default, or the directory you specified with -o DIR).
[!NOTE] Don't forget to stop the endpoint before updating:
sudo systemctl stop trusttunnelTo start the endpoint again after updating:
sudo systemctl start trusttunnel
Please refer to the CONFIGURATION.md for the more detailed documentation on how to configure the endpoint.
The installation directory contains setup_wizard binary that helps generate
the config files required for the endpoint to run:
cd /opt/trusttunnel/
./setup_wizard -h
The setup wizard supports interactive mode, so you could run it and it will ask for data required for endpoint configuration.
cd /opt/trusttunnel/
sudo ./setup_wizard
[!NOTE]
sudois required to manage TLS certificates properly.
The wizard will ask for the following fields, some of them have the default values you could safely use:
0.0.0.0:443 for native deployments (HTTPS on all interfaces).
If you run with Docker port mapping 443:8443, set it to 0.0.0.0:8443.yes if you want to add more users, or no
to continue the configuration process.