Open Source Alternatives LogoOpen Source Alternatives
AlternativesBlogAdvertise
Open Source Alternatives LogoOpen Source Alternatives

Stay Updated

Subscribe to our newsletter for the latest news and updates about Alternatives

Open Source Alternatives LogoOpen Source Alternatives

Handpicked Open Source Alternatives to Paid Softwares

Product
  • Categories
  • Tag
  • Advertise
Resources
  • Blog
  • Collection
  • Submit
  • Advertise your tool
Company
  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Sitemap
Alternatives
  • Claude Code
  • Jira
  • Notion
  • Slack
  • Linear
  • Wispr Flow
  • All alternatives
Copyright © 2026 All Rights Reserved.
Home/Categories/IT Management/Xray-core
icon of Xray-core

Xray-core

Build and self-host a multi-protocol proxy core supporting XTLS, VLESS, and REALITY protocols for private network routing and censorship bypass.

42K starsGoMPL-2.0Active this week
Visit websiteGitHub repo
image of Xray-core
Contents
  1. 01Who Xray-core is for
  2. 02The problem it solves
  3. 03How it solves it
  4. 04Strengths and trade-offs
  5. 05Xray-core vs alternatives
  6. 06Quick start
  7. 07Tech stack
  8. 08FAQ
  9. 09Similar open-source tools
TL;DR

Xray-core is a Go-based network proxy engine implementing XTLS, VLESS, VMess, Shadowsocks, Trojan, WireGuard, and REALITY protocols. It gives operators a self-hosted alternative to commercial VPN services, with full control over routing, protocol selection, and server infrastructure. Licensed under MPL-2.0, it deploys via Docker or a Linux install script and extends with third-party web panels for user management. Best for sysadmins and developers building private network tunnels or proxy servers on their own infrastructure.MPL-2.0 · Go · 42K stars · Active this week

who it's for

Who Xray-core is for#

Sysadmins building private proxy infrastructure

Deploy Xray-core on a VPS to serve multiple clients with fine-grained routing rules. Configure protocol fallbacks, set per-user traffic limits via a panel like Marzban or 3X-UI, and select protocols suited to the network environment.

Skip if:

If you need a consumer-ready VPN with a GUI client app and no server to manage, a commercial VPN subscription is a better fit. Xray-core requires you to operate and maintain the server infrastructure yourself.

Developers embedding a proxy engine in applications

The libXray library and community bindings (Xray-core-python, AndroidLibXrayLite) let you integrate the proxy engine into mobile apps, desktop clients, or backend services. Existing Flutter and Android libraries document the integration path for mobile platforms.

Skip if:

If you only need basic HTTP or SOCKS proxying without protocol diversity or XTLS, a simpler library covers the use case with less integration overhead.

Users in restricted or censored network environments

Run a self-hosted Xray-core instance outside the restricted network and connect via VLESS-XTLS or REALITY, which are designed to resist active probing and traffic classification. Available clients cover iOS, Android, Windows, macOS, and Linux, so one server serves all platforms.

Skip if:

If standard VPN protocols like WireGuard or OpenVPN pass through your network undetected, Xray-core's additional protocol complexity adds setup overhead without proportional benefit.

Teams running shared multi-user proxy services

Paired with a panel like Remnawave or 3X-UI, Xray-core supports per-user accounts, traffic quotas, and subscription link generation for mobile clients. This covers shared proxy services for small teams or groups.

Skip if:

If you need commercial SLA guarantees, dedicated support, or compliance certifications for your network infrastructure, a managed service is more appropriate than a self-hosted proxy core.

the problem

The problem it solves#

Routing traffic on monitored or censored networks forces a choice: rely on commercial VPN subscriptions or accept the restrictions. Commercial providers offer fixed server locations, opaque protocols, and per-seat pricing that scales poorly for teams. You cannot inspect their infrastructure, modify their routing logic, or audit the code running your network traffic. For organizations and individuals who need censorship bypass or private tunneling, this means trusting a third party with all network metadata.

The secondary challenge is protocol diversity. Different network environments block different protocols. An approach that works on one network may fail on another if the underlying protocol fingerprint is recognizable. Xray-core addresses both challenges by providing a multi-protocol engine you run yourself: XTLS and REALITY are specifically designed to resist active probing and traffic classification, which is the pain point commercial VPN protocols commonly face.

how Xray-core solves it

How it solves it#

Multi-protocol proxy engine

Supports VMess, VLESS, Shadowsocks, Trojan, Socks5, WireGuard, and HTTP as inbound and outbound protocols within a single binary. Each inbound and outbound can use a different protocol, allowing mixed configurations without deploying separate services for each client type.

XTLS and REALITY protocol support

XTLS extends standard TLS to reduce timing differences that distinguish proxy traffic from legitimate HTTPS. REALITY builds on this by borrowing certificate configurations from real sites to further resist active probing. Both protocols are designed to make classified traffic harder to detect under deep packet inspection.

DNS resolver and traffic routing rules

Built-in DNS resolver with support for custom DNS servers, domain-level routing, and IP-range rules. Routes specific domains or IP ranges through different outbounds, enabling split-tunneling configurations where only certain traffic passes through the proxy.

Third-party web panel ecosystem

Multiple community panels, including 3X-UI, Marzban, Remnawave, and Hiddify, sit on top of the core and provide a browser interface for user accounts, traffic quotas, subscription link generation, and connection monitoring. The core has no built-in UI; panels are separate open source projects.

Cross-platform client support

Official and community clients cover Windows (v2rayN, Furious), Android (v2rayNG), iOS and macOS (Happ, Streisand), Linux (v2rayA, Furious), and OpenWrt routers (PassWall). The libXray library enables embedding the core in mobile apps via Flutter or Android native code.

strengths · trade-offs

Strengths and trade-offs#

Strengths

  • XTLS and REALITY protocol innovationXray-core originated the XTLS protocol and developed REALITY, both designed to reduce the TLS fingerprint differences that distinguish proxy traffic from legitimate HTTPS. These protocol designs directly address active probing techniques used by deep packet inspection systems, which most commercial VPN implementations do not architect around.
  • 42,000+ GitHub stars with active maintenanceOver 42,000 GitHub stars and 5,900 forks reflect widespread real-world adoption. The repository received commits through October 2026 and maintains only 55 open issues, suggesting a responsive maintainer team rather than a backlogged or stale project.
  • MPL-2.0: auditable and forkableMozilla Public License 2.0 allows commercial use, modification, and distribution. Unlike proprietary VPN protocols, you can inspect the full implementation. File-level modifications to Xray-core itself must remain under MPL-2.0, but building services on top of an unmodified core does not trigger that requirement.
  • Single binary handling multiple protocols simultaneouslyOne running instance handles multiple inbound and outbound protocols at the same time, serving VMess to one client group, VLESS-XTLS to another, and routing WireGuard traffic outbound without deploying separate proxy processes for each protocol.

Trade-offs

  • -No built-in management interfaceXray-core is a headless binary configured via JSON files. There is no built-in dashboard, user management, or traffic statistics panel. Third-party panels like 3X-UI or Marzban provide this functionality but are separate projects requiring their own deployment and maintenance.
  • -JSON configuration complexityRouting rules, DNS overrides, and multi-protocol chains are configured in JSON. Multi-inbound setups with fallbacks and different protocols are not trivial to write correctly, and configuration errors typically surface as silent connection failures rather than clear error messages.
  • -Requires server administration knowledgeDeployment assumes access to a VPS or server, the ability to configure firewall rules, and familiarity with TLS certificates and network routing concepts. Consumer VPN apps abstract all of this; Xray-core does not. Running a production instance means managing updates, uptime, and certificate renewal yourself.
versus alternatives

Xray-core vs alternatives#

Xray-core vs Commercial VPN Services

Xray-core and commercial VPN services like NordVPN and ExpressVPN both route encrypted traffic through an intermediary, but they operate on opposite deployment models: one requires you to run the server, the other runs it for you.

FeatureXray-coreCommercial VPN (e.g., NordVPN, ExpressVPN)
LicenseMPL-2.0 (open source)Proprietary
InfrastructureSelf-hosted (your server)Provider-managed
Protocol selectionVMess, VLESS, XTLS, REALITY, Shadowsocks, WireGuard, TrojanFixed (WireGuard, OpenVPN, proprietary)
Anti-censorship protocolsXTLS and REALITY (active probing resistance)Limited or unavailable
Management interfaceThird-party panels (3X-UI, Marzban)Bundled client apps
Pricing modelServer cost only (no per-seat fee)$3-15/month per user
Code auditabilityFull (MPL-2.0)No

Xray-core is the better choice when you need XTLS or REALITY to handle deep packet inspection (standard WireGuard and OpenVPN fingerprints are detectable in some network environments), when data sovereignty requirements prohibit using third-party infrastructure, or when you are building a shared service for multiple users where per-seat commercial pricing does not scale. A basic VPS to run the core typically costs under $5/month regardless of user count.

Commercial VPN subscriptions are the better choice when you need a zero-configuration consumer experience, consistent global server coverage across 50+ locations for latency management, or an audited no-logs policy with published third-party results. No server management, automatic failover, and bundled apps for every platform justify the subscription cost for non-technical users.

install · quick start

Quick start#

bash
Deploy using the official Docker image or install on macOS via Homebrew.

```bash
docker pull ghcr.io/xtls/xray-core
brew install xray
```
tech stack · detected from GitHub

What it's built on#

Languages
Go
frequently asked

FAQ#

Is Xray-core the same as V2Ray?

No. Xray-core was forked from v2fly/v2ray-core in November 2020. It shares the original codebase but has diverged significantly, adding XTLS, REALITY, XHTTP, and other protocols not present in the v2ray-core upstream. The XTLS and VLESS protocol improvements originated with the Xray project. They are separate projects maintained by different teams.

What protocols does Xray-core support?

Inbound and outbound protocols include VMess, VLESS, Shadowsocks, Trojan, Socks5, HTTP, WireGuard, and DNS. XTLS and REALITY are TLS-layer enhancements available on VLESS connections, designed to help traffic blend with legitimate HTTPS and resist fingerprinting by deep packet inspection systems.

Is Xray-core free for commercial use?

Yes, under MPL-2.0. You can run Xray-core commercially, including using it as part of a paid service. The file-level copyleft means modifications to Xray-core's own source files must be released under MPL-2.0, but building a service on top of an unmodified core does not trigger the copyleft requirement.

Does Xray-core include a web interface or management panel?

No. Xray-core is a headless binary configured by JSON files. Web management panels such as 3X-UI, Marzban, and Remnawave are separate open source projects that wrap the core and provide a browser interface for user management and traffic monitoring. Installing a panel separately is the standard approach for multi-user deployments.

What is the difference between Xray-core and sing-box?

Both are Go-based proxy cores supporting multiple protocols, including Shadowsocks, VMess, and WireGuard. sing-box is a separate project with its own configuration format and routing syntax. XTLS and REALITY support originated in Xray-core and was later added to sing-box. Both projects appear in the same client apps in some cases; the choice typically comes down to configuration syntax preference and which panel ecosystem you are building on.

also worth a look

Similar open-source tools#

Obtainium

Obtainium

Android app updates direct from GitHub and F-Droid

20.3KDartGPL-3.0
mvt

mvt

Mobile forensics toolkit for detecting spyware on Android and iOS

15.3KPythonMVT License 1.1
OpenFlux

OpenFlux

TCP tunneling via Yandex Docs or WebRTC transports

2KGoGPL-3.0
tailcat

tailcat

Encrypted tunnels between machines, no account or IP needed

8.2KGoBSD-3-Clause
airstats

airstats

Sixteen macOS metrics in your menu bar at 0.046% CPU

361SwiftMIT
hysteria

hysteria

Fast and censorship-resistant proxy solution

22.6KGoMIT

Repository

Stars
42K
Forks
6K
License
MPL-2.0
Latest
v26.3.27
Last commit
today
Last verified
Oct 11, 2026
Repo
XTLS/Xray-core ↗

Additional details

Language
Go
Open issues
55
Contributors
274
First release
2020

Categories

IT ManagementSecurity & MonitoringDeveloper Tools

Tags

Infrastructure as CodeCloud NativeDevOps ToolsSecurityAPI Development Tools