WG Tunnel
5.7.5 · GitHub
More about this app
A FOSS Android client for WireGuard and AmneziaWG with auto-tunneling.
WG Tunnel
An alternative FOSS Android client for WireGuard
and AmneziaWG
Report a Bug
·
Request a Feature
·
Ask a Question
Table of Contents
About
WG Tunnel is an alternative Android client for WireGuard and AmneziaWG, inspired by the official WireGuard Android app. It fills gaps in the official client by adding advanced features like auto-tunneling, AmneziaWG support, different app modes like Lockdown (a custom kill switch for leak prevention), and Local Proxy (expose a tunnel over a local SOCKS5/HTTP proxy server) for enhanced privacy, censorship resistance, and flexibility.
Screenshots
Features
- Auto-Tunneling: Automatically activate tunnels based on your device's active network details.
- Deferred Endpoint Bootstrapping: Safely resolves endpoints and updates peers after the tunnel is up for better reliability and leak protection on startup.
- Handshake Monitoring: Real-time handshake monitoring for instant tunnel health feedback.
- AmneziaWG Support: Full support for AmneziaWG 2.0 through 3.1, providing robust censorship protection.
- Split Tunneling: Flexible support for routing specific apps or traffic through the VPN.
- Split & Encrypted DNS: Resolve DNS through the tunnel using plain DNS, DoT, or DoH, and optionally split by domain suffix (tunnel or system).
- Local Proxy Mode: Expose WireGuard tunnels over a local SOCKS5 or HTTP proxy to browsers or firewall apps (like AdGuard).
- Lockdown Mode: Advanced in-app kill switch that blocks all traffic while the tunnel is down.
- Quick Controls: Quick Settings tile and home screen shortcuts for easy toggling.
- Remote Control Support: Intent-based automation for controlling tunnels and auto-tunneling from automation apps (like Tasker).
- Dynamic DNS Handling: Automatically detect and update endpoints on server IP changes without requiring a restart.
- IPv6 Endpoints: Automatically upgrade to IPv6 endpoints or fall back to IPv4 based on network conditions without requiring a restart.
- Android TV Support: Full support for nearly all features on Android TV.
Building
The app consumes published core artifacts from Maven Central by default (libs.bundles.wgtunnel.core). That is enough for most app-only work.
git clone https://github.com/wgtunnel/android
cd android
./gradlew assembleDebug
Local full build (app + core)
To build against a local core checkout (native JNI, backend, parser, hevtunnel), clone core next to this repo:
parent/
android/ # this repository
core/ # https://github.com/wgtunnel/core
cd /path/to/parent
git clone https://github.com/wgtunnel/android
git clone https://github.com/wgtunnel/core
cd android
You also need the core build requirements (JDK 21, Android NDK, make, a C toolchain).
Then switch Gradle from Maven Central to the composite build:
- In
settings.gradle.kts, uncomment the local-devincludeBuild:
// Local dev
includeBuild("../core") {
dependencySubstitution {
substitute(module("com.wgtunnel.tunnel:backend"))
.using(project(":backend"))
substitute(module("com.wgtunnel.tunnel:backend-android-jni"))
.using(project(":backend-android-jni"))
}
}
- In
app/build.gradle.kts, comment out the Maven bundle and uncomment the local-dev implementations:
dependencies {
implementation(project(":logcatter"))
implementation(project(":networkmonitor"))
// implementation(libs.bundles.wgtunnel.core)
// Local dev
implementation("com.wgtunnel.tunnel:backend")
implementation("com.wgtunnel.tunnel:backend-android-jni")
}
- Build from
android/:
./gradlew assembleDebug
Do not commit those Gradle edits. Restore the commented includeBuild and Maven libs.bundles.wgtunnel.core dependency before opening a PR.
Translation
Help translate WG Tunnel on Crowdin.
Acknowledgements
Thank you to the following:
- All of the users that have helped contribute to the project with ideas, translations, feedback, bug reports, testing, and donations.
- WireGuard - Jason A. Donenfeld (https://github.com/WireGuard/wireguard-android)
- AmneziaWG - Amnezia Team (https://github.com/amnezia-vpn/amneziawg-android)
- JetBrains - For supporting open-source developers with free software licenses.
Contributing
Any contributions in the form of feedback, issues, code, or translations are welcome and much appreciated!
For PRs, please make sure to format before submitting.
./gradlew format
CI runs ./gradlew formatCheck, which uses the same files and style as format. If that job fails, run ./gradlew format and commit the result.
If your PR requires core changes, please link the associated PR.
How Shizuku is used
Can detect the current Wi-Fi name for auto-tunneling without location permission via `cmd wifi status` through Shizuku.
This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.
How this app uses Shizuku
Shizuku is used as an optional Wi-Fi detection method that lets auto-tunneling identify the current network without location permission. When the user selects Shizuku detection, the app runs a privileged shell command and parses the result to drive trusted network automation.
- Detect Wi-Fi network: the current Wi-Fi name and hardware address are read from the output of the
cmd wifi statusshell command run through Shizuku, then used to decide when the VPN tunnel should start or stop on trusted or untrusted networks.
Android APIs or commands used
cmd wifi status
Notable details
Shizuku detection is optional alongside the standard and legacy methods, which instead use the system Wi-Fi and connectivity APIs and require location permission. Shizuku detection avoids that location requirement.
Changelog
What's new for version 5.7.5
What's new:
- Auto tunnel race fix on certain devices
- In app updater improvement and fixes for standalone
SHA-256 fingerprints for the 4096-bit signing certificate:
5204d82e766e8aa14dcbb06dc70aebae2bdd812d4d6203cd521a8a685d7d3d80
To verify fingerprint:
apksigner verify --print-certs [path to APK file] | grep SHA-256
Changelog
:bug: Bug Fixes
6d99959- auto tunnel partial tunnel teardown and sync (commit by @zaneschepke)207ec7f- in-app updater to use download manager when available (commit by @zaneschepke)
:recycle: Refactors
6829d1e- bump core socket opts and tunnel healthy ack race (commit by @zaneschepke)
:wrench: Chores
0dbf07c- release 5.7.5 (commit by @zaneschepke)
Permissions
23 permissions requested
Sources
3 sources
Sources
3 sources