ZedSecure: A Multi-Core VPN Client with Xray, Tor, and DNS Tunnels
Published: 2026-10-01 · Author: AI Release · @ai_release1
⚡ The Gist in 5 Seconds - ZedSecure is a VPN and proxy client for Android, Linux, Windows, and macOS that ships with multiple engines out of the box: Xray, sing-box, Psiphon, Tor, DNS tunnels, WireGuard, AmneziaWG, OpenConnect, IKEv2, and SSH. - The Android version is available on Google Play and as an APK in Releases (arm64-v8a for most phones, armeabi-v7a for older ones); desktop builds come as.deb,.rpm,.AppImage,.tar.gz,.msi, portable.zip, and.dmg for Apple Silicon and Intel. - Limitation: the full set of engines is available only on Android. On Linux, Windows, and macOS, only Xray, sing-box, DNS tunnels, and SSH are available. The macOS build is not notarized — for the first launch, right-click and then select Open. ### 🔍 What We Found The project is published on GitHub as CluvexStudio/ZedSecure and is distributed under the AGPL-3.0 license. The core links sing-box, Psiphon, and sing-openvpn, which are licensed under GPL-3.0: Section 13 of GPL-3.0 allows combining them with AGPL-3.0 code, and each part retains its own license. The app core is built with the ./tools/fetch-cores.sh (all engines pinned to fixed commits) and ./tools/build-zedcore.sh scripts — the latter requires Go 1.26.3 and NDK 28 or newer. ./gradlew:app:assembleRelease produces three APKs, one per ABI, while :desktop:packageDeb (or packageRpm, packageMsi, packageDmg) produces the desktop packages. Pushing a v* tag builds Android and all desktop platforms in CI and puts them into a single release; Android and desktop share the same version number. The protocol set per engine is as follows: Xray handles VLESS with Reality, Vision, and XHTTP, plus VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, and AmneziaWG; sing-box covers TUIC, Naive, AnyTLS, ShadowTLS, OpenVPN.ovpn files, and plain sing-box JSON; Psiphon runs through its own network with no server of your own required; Tor runs through obfs4, Snowflake, and Conjure bridges; DNS tunnels use DNSTT, VayDNS, and MasterDNS over UDP, TCP, DoT, or DoH; OpenConnect covers Cisco AnyConnect and compatible gateways; IKEv2 uses the IPsec client built into Android; SSH works standalone or through any of the engines listed above. Engines can be chained with each other in both directions — for example, Xray over Tor or Tor over Xray. Features include importing share links, subscriptions, Xray and sing-box JSON,.ovpn files, Amnezia vpn:// links, and QR codes; automatic selection of the fastest server with automatic failover; per-app routing; a geoip/geosite rule editor; SNI spoofing on rooted devices; a Vault with config export to.zsx (with a password and expiration date); a speed test; an MTU finder; a DNS resolver scanner; and a live log. The interface is Material 3 Expressive with light and dark themes, available in English, Persian, Russian, and Chinese. ### 💡 Why It Matters The idea behind the project is that when one route gets blocked, the next one is already set up: there's no need to keep separate clients for Xray, sing-box, Psiphon, Tor, and DNS tunnels. One tap tests all servers and switches the connection to the fastest one, while engine chaining lets you build non-trivial setups like Xray over Tor. The practical benefit — you can che...
⚡ The Gist in 5 Seconds - ZedSecure is a VPN and proxy client for Android, Linux, Windows, and macOS that ships with multiple engines out of the box: Xray, sing-box, Psiphon, Tor, DNS tunnels, WireGuard, AmneziaWG, OpenConnect, IKEv2, and SSH.
- The Android version is available on Google Play and as an APK in Releases (arm64-v8a for most phones, armeabi-v7a for older ones); desktop builds come as.deb,.rpm,.AppImage,.tar.gz,.msi, portable.zip, and.dmg for Apple Silicon and Intel.
- Limitation: the full set of engines is available only on Android.
On Linux, Windows, and macOS, only Xray, sing-box, DNS tunnels, and SSH are available.
The macOS build is not notarized — for the first launch, right-click and then select Open.
🔍 What We Found The project is published on GitHub as CluvexStudio/ZedSecure and is distributed under the AGPL-3.0 license.
The core links sing-box, Psiphon, and sing-openvpn, which are licensed under GPL-3.0: Section 13 of GPL-3.0 allows combining them with AGPL-3.0 code, and each part retains its own license.
The app core is built with the ./tools/fetch-cores.sh (all engines pinned to fixed commits) and ./tools/build-zedcore.sh scripts — the latter requires Go 1.26.3 and NDK 28 or newer.