# Oblivion Desktop: an unofficial WARP client for Windows, macOS and Linux

> Oblivion Desktop wraps Cloudflare WARP, Gool, Psiphon and Masque behind an Electron interface. Here is how the pieces fit, how to get a first connection running, and where the restrictive licence and the missing kill switch matter.

**bepass-org/oblivion-desktop** — Oblivion Desktop - Unofficial Warp Client for Windows/Mac/Linux

- Repository: https://github.com/bepass-org/oblivion-desktop
- Website: https://github.com/bepass-org/oblivion-desktop/releases
- Stars: 8,392 · Forks: 902
- Language: TypeScript
- License: NOASSERTION
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/bepass-org-oblivion-desktop

## What Oblivion Desktop is, and who ends up installing it

Oblivion Desktop is an unofficial desktop client for Cloudflare WARP, distributed by the bepass-org organisation. The README describes it as providing "a secure, optimised internet access through a user-friendly Windows/Linux/MacOS app using Cloudflare WARP's technology", and it is explicitly positioned as the desktop counterpart of the mobile Oblivion client. The repository's own description calls it an "Unofficial Warp Client for Windows/Mac/Linux".

The audience is narrow but real. A user on a network where the standard WARP client fails to connect needs a different route to the same endpoint, and Oblivion Desktop exposes several. The method table lists WARP, Gool, Cfon (Psiphon) and Masque. Someone who simply wants a commercial VPN with a support contract is not the target reader here; someone who already knows what WARP is and cannot reach it is.

The project is written in TypeScript with a Golang backend. The README claims a "Custom WireGuard implementation in Golang" behind the interface. That split matters for anyone evaluating it: the UI is Electron, and the tunnelling work happens outside the JavaScript layer.

## Four connection methods and three network modes

The README's feature table is the clearest description of the architecture. Under Method it lists WARP, Gool, Cfon (Psiphon) and Masque. Under Network configurations it lists Proxy (marked "No changes"), System Proxy (with PAC) and TUN (with Sing-Box). Those are two separate axes: which upstream service carries your traffic, and how that traffic is captured on the machine.

The distinction is practical. Proxy mode leaves system settings alone, which suits a user who only wants one application routed. System Proxy mode writes a PAC file so the operating system decides what goes through. TUN mode routes at the network layer through Sing-Box, which is the only one of the three that can carry traffic from applications that ignore proxy settings.

Routing rules are available for System Proxy and GeoDB. That combination lets you send some destinations through the tunnel and leave others direct, which is the usual requirement for people who need local banking or government sites to keep working. The README does not document the rule syntax, so treat the UI as the source of truth for what each rule means.

A Scanner, a Ping tool and a SpeedTest are listed under Other, alongside accessibility options and an in-app updater marked as Windows-only. The same table marks Kill Switch with an empty checkbox. That is an honest disclosure, and it should shape how you think about the tool: if the tunnel drops, nothing in the documented feature set stops traffic from falling back to your normal route.

## Installing Oblivion Desktop and making a first connection

The README points at the releases page rather than a package manager. Builds are published per operating system and architecture: Windows installers and portable archives for x64, arm64 and ia32, macOS DMG and ZIP for arm64, and Linux packages. The Windows compatibility line in the download table reads 10+.

Because there is no npm or Homebrew instruction in the README, the reliable path is to download the asset that matches your machine. On Linux, the repository also ships an install script; the README's download table links it, and the project's own documentation is the place to confirm the exact invocation before running anything as root.

Once the app is open, the workflow is: pick a method, pick a network configuration, then connect. The README does not document a command-line interface, so there is no shell snippet to reproduce here. What you should see after connecting is the connection state change in the interface and, in System Proxy or TUN mode, a change in how the operating system routes traffic. In plain Proxy mode the README says no changes are made, so nothing outside the app should behave differently.

If you build from source instead of downloading, package.json defines the scripts. The prepare step downloads binaries and installs Husky, and postinstall runs a TypeScript script:

```bash
npm install
npm run build
npm run package
```

Those three commands come from the scripts block in package.json. Building is not the supported route for end users, and the repository's CONTRIBUTING.md is the file to read before attempting it.

## The licence is the first thing to read, not the last

The README badge says "License-Restrictive", and package.json sets the license field to "Restrictive". That is not an OSI identifier. The repository carries a LICENSE.md at the top level, and it is the only document that can tell you what you are permitted to do.

This matters more than usual because the README simultaneously describes the project as "Free and Open Source" and mentions "community contribution" and "transparent builds via GitHub Actions". Those two statements sit awkwardly next to a restrictive licence. The source is visible and the build pipeline is public, but visibility is not the same as an open source licence, and the repository metadata does not claim one.

I am not going to guess at the terms. If you intend to redistribute the application, bundle it into a product, or fork it, read LICENSE.md in full before you do anything else. If you are an individual installing it for personal use, the practical question is narrower, but the answer still lives in that file and not in the README's marketing line.

## Where Oblivion Desktop is the wrong choice

No kill switch. The feature table leaves that row unchecked, so on a dropped tunnel the operating system reverts to its normal route. For a user whose threat model includes traffic leaking at the moment of disconnection, that is a disqualifying gap, and no amount of method variety compensates for it.

The project is also unofficial. It is not published by Cloudflare, and the README says so directly. Anyone whose compliance rules require a vendor relationship, a support contract or a signed security review will not get one here. SECURITY.md exists in the repository, which tells you where to report a problem, not that anyone has audited the result.

Method support is a moving target. WARP endpoints get blocked, Psiphon and Masque behave differently across networks, and the maintainers are reacting to conditions rather than controlling them. A configuration that works today may need a different method next month. The in-app updater is Windows-only according to the README, so macOS and Linux users should expect to check the releases page themselves.

Finally, the last push to the repository was on 2026-06-30. That is recent enough that the project is not abandoned, but it is not evidence of a release cadence either: the most recent release listed is v3.11.0 from 2025-11-10.

## How it differs from the standard WARP client and from Sing-Box alone

The official Cloudflare WARP client is the obvious comparison. It is first-party, it is supported by the company that operates the endpoints, and it does one thing. Oblivion Desktop does not replace it so much as route around it: the point of having WARP, Gool, Cfon and Masque in one interface is that when one path is blocked, another may not be. That is a capability the official client does not offer, and it is the reason this project exists.

Sing-Box is the other reference point, and the relationship is closer than it looks. Oblivion Desktop uses Sing-Box for its TUN mode, so a user comfortable with Sing-Box configuration files could assemble something similar by hand. The difference is the GUI, the bundled method switching, the Scanner and Ping tools, and the fact that you do not need to write a config to change approach. If you already maintain a Sing-Box setup you like, Oblivion Desktop is a convenience layer over part of the same machinery, not a replacement for your routing rules.

Against a commercial VPN the trade is straightforward: you give up a support desk and a kill switch, and you get a client built specifically for reaching Cloudflare's network from places where the direct route is interfered with.

## Maintenance, updates and what to check before depending on it

Upgrade cost depends on your platform. Windows users get an in-app updater, so upgrades are a button. macOS and Linux users download a new asset from the releases page each time, which is a manual step and easy to defer. There is no documented package repository for either platform, so no automatic upgrade path is described.

Building from source carries its own cost. The prepare and postinstall scripts pull binaries and native dependencies, and the build runs webpack through the .erb configuration directory. That is a normal Electron setup, but it is not a five-minute task, and it is not what the project asks end users to do.

The changelog is the document to watch for behaviour changes, since CHANGELOG.md sits at the top level and the release list shows three releases in November 2025 alone. Before you depend on the tool, verify four things: that a release asset exists for your architecture, that your chosen method actually connects from your network, that your routing rules send the right destinations through the tunnel, and that the LICENSE.md terms match how you intend to use it. FAQ.md and DOCS.md in the repository are the next places to look when the README runs out.

## Conclusion

Oblivion Desktop suits users on Windows, macOS or Linux whose normal route to Cloudflare WARP is blocked or unreliable, and who want to switch between WARP, Gool, Psiphon and Masque without editing configuration files by hand. It is the wrong tool if you need a kill switch, because the feature table marks that row unchecked, or if you will not accept a licence that package.json labels Restrictive. Before relying on it, check the LICENSE.md text yourself, confirm a release asset exists for your architecture, and test one method at a time rather than trusting the default.

## FAQ

### How does Oblivion Desktop work?

It is a desktop client that connects through Cloudflare WARP and other methods, with a TypeScript interface over a Golang backend that the README describes as a custom WireGuard implementation. You choose a method (WARP, Gool, Cfon or Masque) and a network configuration (Proxy, System Proxy with PAC, or TUN with Sing-Box).

### Is Oblivion Desktop available on PC?

Yes. The README publishes Windows installers and portable archives for x64, arm64 and ia32, with Windows 10+ listed as the compatibility line, alongside macOS DMG and ZIP builds for arm64 and Linux packages.

### Can you play Oblivion on a Mac?

This question is about the game, not this project. Oblivion Desktop does ship a macOS build: the download table lists a DMG and a ZIP for arm64.

### how to use oblivion desktop

Open the app, select one of the four methods, select a network configuration, and connect. Proxy mode leaves system settings unchanged, System Proxy mode applies a PAC file, and TUN mode routes through Sing-Box. The README does not document a command-line interface.

### what is oblivion desktop

It is the unofficial desktop version of the Oblivion mobile client, built by bepass-org. The README describes it as providing secure internet access on Windows, Linux and macOS using Cloudflare WARP's technology, with additional Gool, Psiphon and Masque methods.

### is oblivion desktop safe

The README does not make a security claim beyond describing the WireGuard implementation and the encryption it provides, and the project is explicitly unofficial, so it is not published or audited by Cloudflare. The feature table marks Kill Switch as unchecked, so traffic is not blocked if the tunnel drops. Read SECURITY.md and LICENSE.md before deciding for yourself.

## Sources

- [bepass-org/oblivion-desktop on GitHub](https://github.com/bepass-org/oblivion-desktop)
- [Issues](https://github.com/bepass-org/oblivion-desktop/issues)
- [Project website](https://github.com/bepass-org/oblivion-desktop/releases)
- [README](https://github.com/bepass-org/oblivion-desktop/blob/main/README.md)
- [Releases](https://github.com/bepass-org/oblivion-desktop/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bepass-org-oblivion-desktop
