This material explains lawful network security and configuration scenarios. Follow the rules that apply in your location.
What v2RayTun is and which profiles it supports
Under the hood, v2RayTun runs Xray, the core used by many VLESS clients and servers. The app stores your profiles, starts the core and asks the operating system to route traffic through it, which is why Android and iOS show a VPN indicator while it's connected. Its store listings name VLESS (with Reality), VMess and Trojan among the supported protocols.
A profile reaches the app in one of two forms:
- A single key is one line starting with vless:// that describes one server. If the server details change, you need a new key.
- A subscription link is an ordinary https:// address. The app downloads a list of profiles from it and can refresh that list later without a new import.
Flex-VPN offers VLESS + Reality as its alternative profile type, for networks where a different connection method works better. It runs over TCP with TLS, and the connection looks like ordinary HTTPS traffic. The service's Telegram bot issues ready keys and subscription links, and renewing a plan normally doesn't require a new one. For background, see what VLESS is and how vless:// links are built.
Where to download v2RayTun: official sources
A VPN client handles everything your device sends, so install it only from official sources:
| Platform | Official source | Notes |
|---|---|---|
| Android | Google Play | Updates install through the store |
| iPhone and iPad | App Store | Free to download, with optional in-app purchases |
| Mac | Mac App Store | The same listing as the iPhone and iPad app |
| Windows | The developer's website, v2raytun.com, or Windows Package Manager (winget) | The winget package ID is v2RayTun.Windows |
Searches for a v2RayTun APK mostly lead to third-party mirror sites. On Android, install from Google Play. If you can't, use a direct download only when the developer's own website offers one, and skip anything advertised as a modified, "premium" or "unlocked" build.
A repackaged client can read or redirect all traffic you send through it. If the publisher name on a download page doesn't match the official store listing, don't install it. Code repositories that re-upload the app's installers aren't an official source either.
Links to the clients that work with our profiles, including the Flex VPN app for Android, are on the apps page.
Importing a vless:// key from the clipboard or a QR code
A VLESS key is a single line of text. Here is a placeholder that shows the structure (it isn't a working key):
vless://your-uuid@server.example.com:443?encryption=none&flow=xtls-rprx-vision&type=tcp&security=reality&sni=www.example.com&fp=chrome&pbk=public-key&sid=short-id#My-profile
- your-uuid is your user ID. It works like a password, so keep the whole key private.
- server.example.com:443 is the server address and port.
- encryption=none is normal for VLESS: protection comes from the TLS or Reality layer, not from VLESS itself.
- The other parameters set the transport (type), the security layer (security), the TLS server name (sni), the browser TLS fingerprint the client presents (fp), the Reality public key and short ID (pbk, sid) and the XTLS Vision mode (flow).
- Text after the # sign is only the display name in the app.
You never need to edit these fields. If an import fails, copy the key again in full.
Import from the clipboard
- Copy the entire key, from vless:// to the end of the line. Copy it from the original message, because forwarded or quoted copies are sometimes cut short.
- Open v2RayTun and tap the add button (usually a plus sign).
- Choose the option to import from the clipboard. The new profile appears in the list under the name from the end of the key.
Import from a QR code or an import link
If the key is shown as a QR code, for example on a computer screen, choose the scan option in the same add menu and point the camera at it; the app needs camera access only for this. Some providers also offer a button that adds the profile to v2RayTun directly through the app's import link.
Adding a v2ray subscription link and updating servers
A v2ray subscription is an https:// address that returns a list of share links, usually base64-encoded. You add it once and the app fetches every profile on it.
- Copy the subscription link. It starts with https://, not vless://.
- In v2RayTun, tap the add button and import from the clipboard, as with a single key. The app recognizes the subscription address and adds its profiles as a group. If your version has a separate subscriptions section in its settings, add the URL there instead.
- Wait a moment while the list downloads, then pick a server from the group.
- Repeat on your other devices, using each device's own key or link.
To refresh the list, use the update action in the subscription group's menu. The subscription server can also set an automatic refresh interval. Single keys never update this way, which is the main reason to prefer a subscription.
Your subscription link is a credential: anyone who has it can import your profiles. Keep it out of shared chats and screenshots, and ask your provider for a new one if it leaks.
Connecting and checking that traffic uses the VPN
- Tap the profile you want so it's marked as the active one.
- Tap the connect button.
- The first time, approve the system prompt. Android asks you to allow a VPN connection request; iPhone and iPad ask to add a VPN configuration and confirm it with your passcode, Face ID or Touch ID.
- Look for the system indicator: a key or VPN icon in the Android status bar, or a VPN badge in the iPhone status bar or Control Center.
The indicator only tells you the tunnel is up. To confirm that traffic actually flows through it:
- Check your public IP. Open any IP lookup page with the VPN off, then on. The address and its location should change to match the server you picked.
- Test the server. If the app offers a ping or delay test, use it to spot a server that isn't responding; it doesn't measure download speed.
- Look for DNS leaks. The guide on how to test and fix DNS leaks explains what a good result looks like.
v2RayTun for Windows: system proxy or TUN
Desktop Xray clients usually offer two routing modes. System proxy mode covers browsers and other programs that follow the Windows proxy setting, while programs that ignore it connect directly. TUN mode creates a virtual network adapter that captures traffic from every app, and it may ask for administrator rights. If some programs stay outside the VPN, switch to TUN mode where your version offers it.
Split tunneling in v2RayTun: app and domain rules
Split tunneling decides which traffic uses the VPN and which goes over your regular connection. It's useful for local devices such as a printer or a network drive, and for apps that don't work properly while a VPN is on. The split tunneling guide covers the concept; here is how it works in v2RayTun.
v2RayTun on Android: choose apps
In v2RayTun, per-app routing is available on Android: you can limit the VPN to selected apps or exclude selected apps from it. The wording of the setting varies between versions. Pick one approach, then disconnect and reconnect so the system applies the new list.
v2RayTun on iOS: domain and IP rules
iOS doesn't let App Store VPN apps route individual apps; per-app VPN is available only on devices managed by an organization through MDM. On iPhone and iPad, v2RayTun uses routing rules instead, sending chosen domains or IP ranges directly or through the proxy. If devices on your home network stop responding while you're connected, check that private ranges such as 192.168.0.0/16 go direct. On Mac and Windows, check the routing section of the app's settings.
Rules that come with a subscription
A subscription can also deliver a routing set, and v2RayTun gives it priority over the routing configured in the app. If your manual rules seem to be ignored, check whether the subscription supplies its own.
v2RayTun vs Happ: which client to use
Both apps are clients for VLESS profiles, and a standard VLESS subscription link imports into either. This compares the two apps, not VPN services.
| v2RayTun | Happ | |
|---|---|---|
| Platforms | Android, iPhone and iPad, Mac, Windows | Android, iOS, Windows, macOS |
| Role with our profiles | Compatible client for a VLESS subscription | Documented client for VLESS + Reality subscriptions |
| Server list updates | Manual refresh, plus automatic refresh if the subscription sets an interval | Updates the server list from the subscription on its own |
If you already use v2RayTun for other profiles or prefer its interface, there's no need to switch: add your VLESS subscription there. If you're starting from scratch with Flex-VPN, the Happ setup guide is the path documented step by step, and Happ keeps the server list current by itself. Whichever client you choose, give each device its own profile.
v2RayTun not connecting: what to check
Work through these checks in order.
The key or subscription won't import
- The copied text must start with vless:// for a key or https:// for a subscription. Stray characters before it, a line break inside it or a missing end make the import fail.
- Copy from the original message. Forwarded or quoted copies are often truncated.
- Importing a subscription needs a working connection, because the app downloads the list at that moment. Turn off other VPN apps first.
Connected, but nothing loads
- Switch to another server in the subscription. If others work, the problem is with that location, not your setup.
- Set date, time and time zone to automatic. TLS handshakes, Reality included, can fail when the device clock is far off.
- Close other VPN apps. Android and iOS keep one VPN active at a time, and starting a second one disconnects the first.
- Update the subscription. If server details changed, an old profile may point to settings the server no longer accepts.
- Check that your plan is active and the device is within your plan's device limit.
- Try another network, such as mobile data instead of Wi-Fi, to see whether the problem follows the device or the network.
It disconnects after a while
- On Android, exclude v2RayTun from battery optimization so the system doesn't stop it in the background.
- On Windows, check whether antivirus or firewall software is interfering with the virtual adapter.
- A brief drop when the phone switches between Wi-Fi and mobile data is normal: existing connections end, and new ones start on the new network.
If none of this helps, the general VPN troubleshooting guide covers network-level causes. When you contact Flex-VPN support (@vpn_flex_support in Telegram), include the exact error text, your device model and the app version.
Frequently asked questions
Is v2RayTun free?
The app is free to download from the official stores, and the App Store listing includes optional in-app purchases. It doesn't come with servers, so you still need a profile from a VPN provider or your own server.
Is there a v2RayTun app for Windows?
Yes. Besides the developer's website, the Windows version is published in Windows Package Manager under the ID v2RayTun.Windows, so you can install it with the command winget install -e --id v2RayTun.Windows.
Does v2RayTun work on iPad and Mac?
Yes. One App Store listing covers iPhone, iPad and Mac. The listing shows the minimum iOS, iPadOS and macOS versions, so check it if the app won't install on an older device.
Can I use the same subscription in v2RayTun and Happ?
Yes, a standard VLESS subscription link imports into both apps. On one device, run one app at a time, since only one VPN can be active; for a second device, use that device's own profile.
Can I import an AmneziaWG key into v2RayTun?
No. AmneziaWG is a WireGuard-based protocol with its own key format, and those keys go into the Amnezia VPN app. Use your VLESS key or subscription link in v2RayTun.
How do I update servers in v2RayTun?
Run the update action on the subscription group, and the app downloads the current list from your subscription link. Single vless:// keys don't update, so replace them when the server details change.