Amnezia VPN Client: a desktop and mobile client that deploys its own VPN server
Amnezia VPN Client (Desktop+Mobile)
At a glance
- What is it?
- Amnezia is a GPL-3.0, Qt-based VPN client for Windows, macOS, Linux, Android and iOS that installs VPN containers on a server you control. This review covers how the server deployment works, how to build the client, and where the approach breaks down.
- Who is it for?
- Amnezia VPN Client fits people who already own a VPS and want a GUI that turns an IP address, an SSH login and a password into a running VPN endpoint, including obfuscated protocols for networks that block plain WireGuard. It is the wrong choice if you want a subscription provider with no server to manage, or if you need a headless CLI on the server itself.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 2 days ago.
- What is it written in?
- Mainly C++, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem Amnezia solves: a VPN endpoint you own, without the server admin work
Most VPN clients assume someone else runs the server. You buy a subscription, receive a config, and connect. Amnezia inverts that. Its stated key feature is that it "enables you to deploy your own VPN server on your server", and the README describes the flow plainly: enter your IP address, SSH login and password, and Amnezia installs VPN docker containers on the machine and connects to the VPN. The client is the installer, the configurator and the tunnel in one application.
The audience follows from that. Someone with a VPS and no interest in hand-writing WireGuard keys or an OpenVPN PKI gets a graphical path from a bare server to a working tunnel. The second audience is people on networks that block or fingerprint standard VPN protocols. Amnezia ships protocols with traffic masking: OpenVPN over the Cloak plugin, Shadowsocks (OpenVPN over Shadowsocks), AmneziaWG and XRay. Plain OpenVPN, WireGuard and IKEv2 are there too, for networks that do not interfere.
The project is not a service. There is no Amnezia-operated exit node in this repository. The client talks to a server you supply, which is why the server-side cost and jurisdiction questions land on you rather than on a provider.
How the client, the SSH deploy step and the protocol containers fit together
The architecture visible in the repository separates the GUI from the privileged work. The top-level entries include client/, service/, ipc/, common/ and deploy/. The client/ directory holds the Qt user interface shared across desktop and mobile targets. The service/ directory is the piece that performs privileged operations, and ipc/ is the inter-process channel between the two, which is why the build requirements list the Qt Remote Objects module: the client and the helper process communicate over Qt's remote-object mechanism rather than by running everything as root inside the UI process.
Protocol support is not reimplemented from scratch. The README's Tech section lists OpenSSL, OpenVPN, Qt, LibSsh, WireGuard, Xray-core and Conan as the open-source projects AmneziaVPN uses. LibSsh is what makes the deployment story work: the client opens an SSH session to the address you type, then pushes the container setup over that session. Conan supplies the C++ dependencies at build time, and the conanfile.py at the repository root is the manifest for them.
Traffic masking is implemented by wrapping one protocol inside another. OpenVPN over Cloak and OpenVPN over Shadowsocks both keep OpenVPN as the tunnel and add a layer that changes what a network observer sees. AmneziaWG is the project's own variant of WireGuard, documented at docs.amnezia.org rather than in this repository. XRay is a separate core, listed alongside the others in the Tech section. The README also notes AmneziaWG configuration support on Keenetic beta firmware, which is a router-side integration rather than a client feature.
Installing Amnezia VPN Client on Windows, macOS, Linux, Android, iOS or via a mirror
For end users the README does not give a package-manager command. It points to the downloads page on amnezia.org, with a second download button that goes to a storage.googleapis.com mirror, and the tip above those buttons explains why: "If the Amnezia website is blocked in your region, you can use an Alternative website link." All releases are also listed on the GitHub releases page, where the most recent tags are 5.0.3.0, 5.0.2.1 and 5.0.2.0. The README does not document a Linux distribution package, so treat the downloads page as the install path for desktop and the app stores as the path for mobile.
Building from source is documented. The first step is the submodule pull, because the repository depends on code that is not in the main tree:
git submodule update --init --recursiveAfter that, the build requirements are CMake, a platform compiler toolchain, Qt 6.10 or newer with the Core module for the target platform plus the Qt 5 Compatibility module and Qt Remote Objects, and the Conan package manager. On macOS the README says Conan can come from homebrew or a .venv in the project root; on other systems it must be on PATH.
The README directs builders to the scripts in the deploy directory rather than to raw CMake invocations, and notes that the scripts find dependencies automatically when they sit in default installation paths. When they do not, you override the locations with environment variables. The README gives QT_INSTALL_DIR for the Qt root, and the excerpt ends mid-sentence there, so check the rest of the hacking guide for the remaining variables before assuming a full list. Optional installer dependencies are the Qt Installer Framework on Windows and Linux and the WIX toolset on Windows.
A first real use, once the app is running, is the server deployment the README describes: enter the IP address, SSH login and password of a machine you control, and let Amnezia install the VPN docker containers and connect. You should end up with a saved server entry in the client and an active tunnel. The README does not describe what the client prints if the SSH credentials are wrong or if Docker is missing on the target, so budget time for reading the troubleshooting documentation at docs.amnezia.org before blaming the client.
Where Amnezia VPN Client is the wrong tool
The client assumes you have a server and administrative access to it. If you do not own a VPS, or your hosting provider blocks the ports the containers need, the automatic deployment has nothing to talk to. That is not a bug in the client; it is the shape of the product. Someone who wants a VPN in ten minutes with no infrastructure should use a commercial provider instead.
Building from source is heavier than the feature list suggests. Qt 6.10 or newer is a recent requirement, and the Qt 5 Compatibility module plus Qt Remote Objects are not part of every Qt installation. Conan has to be on PATH on Linux and Windows. This is a C++ desktop application with platform toolchains per target, not a Python script you clone and run.
The repository layout shows a dev default branch. That is where the build badge points and where translations are collected, so anyone tracking source builds is tracking development work rather than a stabilised release line. The tagged releases exist, but the README's own instructions for contributors route through dev.
Finally, the README does not document rollback. If the container deployment on your server goes wrong, there is no described uninstall or revert procedure in the README. The troubleshooting page is the place to look, and the absence of a documented rollback is worth knowing before you point the client at a server that also hosts something else.
Amnezia compared with the official WireGuard and OpenVPN clients
The official WireGuard client and the official OpenVPN client both take a configuration file that someone else produced. You generate keys on the server, copy a config to the device, and the client connects. They are small, they do not need Qt, and they do not open SSH connections to anything.
Amnezia does the server side too. The README's selling point is that the client installs the containers for you, which is a different division of labour: the official clients assume the endpoint already exists, Amnezia creates it. The cost of that convenience is a much larger application with a privileged service component and a dependency stack that includes Qt, OpenSSL, LibSsh, OpenVPN, WireGuard and Xray-core.
The obfuscation layer is the other real difference. The official WireGuard client speaks WireGuard. Amnezia also speaks AmneziaWG, OpenVPN over Cloak, OpenVPN over Shadowsocks and XRay, which matters on networks that detect or block the standard handshakes. If your network does not interfere with WireGuard, the official client is the smaller tool for the same job. If it does, the official client has no answer and Amnezia does.
Licence, third-party components and the cost of staying current
The repository is GPL-3.0, with the LICENSE file at the top level. That matters if you plan to redistribute a modified client or bundle it into a product: the GPL-3.0 obligations travel with the code. The repository also carries THIRD_PARTY_LICENSES.md, which is where the terms for the bundled OpenVPN, WireGuard, Xray-core, OpenSSL and other components are collected. Read both files together before shipping anything derived from this code. This is a description of what the repository contains, not legal advice.
Upgrade cost depends on how you consume the project. Users of the published builds follow the releases page, where 5.0.3.0 landed on 2026-09-18, 5.0.2.1 on 2026-09-03 and 5.0.2.0 on 2026-08-31. The last push to the repository was on 2026-09-18, so the project is being worked on, but the cadence of point releases means anyone building from source should expect to rebuild against a moving dev branch rather than a frozen tag.
Source builders carry the heaviest ongoing cost. Qt version bumps, Conan recipe changes in recipes/ and conanfile.py, and submodule updates all land between releases. The README's translation workflow also runs through GitHub Actions artifacts rather than a simple file edit, which adds a step for anyone maintaining a localised fork.
Editorial conclusion
Amnezia VPN Client fits people who already own a VPS and want a GUI that turns an IP address, an SSH login and a password into a running VPN endpoint, including obfuscated protocols for networks that block plain WireGuard. It is the wrong choice if you want a subscription provider with no server to manage, or if you need a headless CLI on the server itself. Before adopting it, confirm that Qt 6.10 or newer with the Qt 5 Compatibility and Qt Remote Objects modules is available for your platform, and read THIRD_PARTY_LICENSES.md alongside the GPL-3.0 LICENSE to understand what the bundled OpenVPN, WireGuard, Xray-core and OpenSSL components add.
Frequently asked questions
Is Amnezia VPN Client free to use?
The client source is published under GPL-3.0, so the software itself is free to build and use under that licence. The README also links to a paid option, "Get Premium for 6 or 12 months", which is separate from the open-source client.
What is Amnezia VPN Client?
It is an open-source VPN client for desktop and mobile whose key feature is deploying your own VPN server on your own machine. The README describes entering an IP address, SSH login and password so the client installs VPN docker containers and connects.
Where can I find the Amnezia config file?
The README does not describe a config file format or a path for one. It documents the client connecting to a server you supply and the source tree's top-level layout, so configuration details are not covered in the README.
How do I install Amnezia VPN Client on Ubuntu?
The README points to the downloads page on amnezia.org, with a mirror link for regions where the main site is blocked, and does not document a distribution package for Linux. Building from source requires CMake, a compiler toolchain, Qt 6.10 or newer with the Qt 5 Compatibility and Qt Remote Objects modules, and Conan on PATH, with build scripts in the deploy directory.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/amnezia-vpn-amnezia-client)