The repository is Xray-VPN-OneClick and the npm package is xray-manager
🚀 5分钟部署 VLESS+Reality VPN | 访问 ChatGPT/Claude/Google | npm CLI 管理工具 | One-Click Xray Server with Traffic Stats | 科学上网 翻墙 梯子 魔法
At a glance
- What is it?
- A TypeScript CLI and shell installer for a VLESS plus Reality Xray server, with user management, traffic quotas and a subscription service. MIT licensed, last pushed on 2026-05-18, and documented in Chinese with the English version filed under docs.
- Who is it for?
- Xray-VPN-OneClick is a practical choice if you already have a small Linux server with a public IP and want a Reality endpoint without buying a domain or obtaining a certificate, because the installer generates the UUID and keys, wires up systemd and prints client configuration on the way out.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 137 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The repository is Xray-VPN-OneClick and the published package is xray-manager
Two names for one project, and the install path you are pointed at first uses neither of them. The lead command downloads scripts/install.sh straight from the repository:
wget https://raw.githubusercontent.com/DanOps-1/Xray-VPN-OneClick/main/scripts/install.sh -O xray-install.sh && sudo bash xray-install.shThe npm route is a different product surface: npm install -g xray-manager followed by sudo xm install, and the manifest registers two binary names, xray-manager and xm, both pointing at the same compiled file, dist/cli.mjs. The two name fields point at each other as well, with the manifest homepage set to the GitHub readme and the repository homepage field set to the npm package page. The version in the manifest is 2.0.1, which matches the newest tag v2.0.0 and v2.0.1 pair, v2.0.1 published on 2026-04-21, while the default branch was last pushed on 2026-05-18, so about a month of commits sits past the newest release. Node 18 or newer is required, and the guide says so on the npm line only.
Fourteen badges, two pointing at the same npm page, none with text
The header carries fourteen badges grouped into four commented sections for core, continuous integration, technology stack and community. Not one of them has a label: each is written as a link with nothing between the brackets, so the render is fourteen unlabelled links. Two of the fourteen point at the identical npm page for xray-manager, which is the only duplicated target in the block. The rest name the stargazers list, the network members graph, the actions workflow, a codecov report, the licence file on main, the commit list, the repository itself, the REALITY project, the TypeScript and Node.js sites, the pull requests and the issues. The presence of a coverage badge is consistent with the manifest, which defines test:coverage. Above the badges sit two more empty anchors, one to the repository and one to its fork, and the star appeal that follows them asks directly for a star as the motive for further updates.
Two of the twelve table-of-contents anchors carry a stray variation selector
The directory section lists twelve headings as links. Ten of them are written in the usual form, a hash, a dash and the heading text. Two are not. The service management entry and the uninstall entry both put an extra character between the hash and the dash, a variation selector carried over from the emoji in the heading itself, so their targets read with a selector wedged in after the hash while the ten working ones do not have it. GitHub builds heading anchors from the heading text, and the selector is not part of that text, so those two links do not land on their sections. Nothing in the file signals the problem, and both entries are the ones a reader is most apt to follow after a failed install, since one of them covers service management and the other covers removal and cleanup.
The interface preview is a caption with no image beside it
The screenshot section is a centred div containing a single paragraph of italic text describing a modern interactive management interface with service management, user management and traffic quota support. There is no image element in it. Meanwhile three PNG files are committed at the repository root, icon.png, interface.png and social-preview.png, so the material for that preview exists in the tree without being referenced. The document's structure repeats the pattern at a larger scale. The use cases and the main features sections are raw HTML tables built from table, tr and td cells with width attributes and emoji prefixes on every heading, rather than Markdown, and the protocol comparison is a Markdown table with six columns. Two of the three presentations therefore behave differently depending on where the file is rendered, which is worth knowing before the text is reused elsewhere.
The feature list names curl and no curl command exists
The deployment feature list has an item for multiple installation methods and names three of them: wget, curl and git clone. The three methods actually documented are wget fetching the script directly, wget fetching it through a mirror proxy for servers inside China, and git clone followed by running install.sh from the scripts directory. No curl command appears anywhere in the file. The same kind of drift runs through the system requirements. The one-line statement asks for Ubuntu 22.04 or newer, Debian 11 or newer and CentOS 9 or newer. The detailed table adds Kali 2023 or newer to the Debian family and adds Fedora 39 and Amazon Linux 2023 as a separate row, and it recommends Debian 12 while the minimum column says 11. Memory is given twice, 512 MB as the floor and 1 GB as the recommendation, alongside a single core and 10 Mbps of bandwidth.
The reason to use Reality is stated as four claims with no evidence attached
The protocol section makes four claims for VLESS plus Reality: that its traffic is identical to a real TLS 1.3 connection, that no domain purchase or certificate configuration is needed, that performance loss is very small and close to a direct connection, and that active probing cannot identify proxy characteristics. The first claim is what the security feature row in the earlier table restates as traffic features indistinguishable from ordinary TLS. The second is the one with the clearest operational consequence, and it is why the system requirements ask for a public IP and never mention a domain name. Against those claims sits a five-row comparison table with star ratings for speed, security, anti-detection and configuration difficulty. Nothing cites a measurement. The table also contains an odd pair: Shadowsocks is rated easiest to configure at five stars and weakest on anti-detection at two, while traditional V2Ray is marked obsolete.
Every platform has a named client except iOS, which needs a US account
The client table names one recommended client per platform and links its release page: v2rayN on Windows, V2rayU or V2RayXS on macOS, v2ray-core or Qv2ray on Linux, and v2rayNG on Android. The iOS row is the exception. It lists Shadowrocket and Quantumult X from the App Store, and appends a note that a US region account is required. That is the only documented platform constraint in the whole client story, and it sits under a feature list that claims full platform coverage across Windows, macOS, Linux, Android and iOS. For Clash, the file recommends Clash Verge Rev by name and gives five reasons, among them cross-platform support, a modern graphical interface, complete VLESS plus Reality support, built-in rule management and subscription, and an open source licence. The subscription service is also listed under management features, where clients are said to update themselves from it.
The build type-checks without emitting, yet the manifest declares a types file
The manifest has eleven runtime dependencies and no dev-only ones in the visible block, which is the signature of a terminal interface rather than a library: react and ink for the display, commander for arguments, @inquirer/prompts for interactive questions, cli-table3 for tables, clipboardy for copying a generated link, qrcode-terminal for the code, fuse.js for search, ora for spinners, chalk for colour and update-notifier for the self-update the feature list promises. Two inconsistencies sit next to that. The build script runs the TypeScript compiler with no emit flag and then hands off to a separate esbuild configuration file, so the compiler stage produces no output while the manifest still points its types field at dist/index.d.ts. And the entry fields disagree in kind, with main set to dist/index.js, the binary at dist/cli.mjs, no type field and no exports map, so the two entry artifacts are interpreted as different module systems.
Editorial conclusion
Xray-VPN-OneClick is a practical choice if you already have a small Linux server with a public IP and want a Reality endpoint without buying a domain or obtaining a certificate, because the installer generates the UUID and keys, wires up systemd and prints client configuration on the way out. It is not the right tool if you need iOS clients without a US region App Store account, if you want a protocol comparison you can rely on, since the five-protocol table is an unsourced star rating, or if you need a supported curl installer, because the feature list names curl and no curl command appears. Before you install, read the uninstall section and the retention note on what the script writes under root, and check the minimum distribution versions yourself, because the one-line requirement and the detailed table do not list the same set.
Frequently asked questions
What does Xray-VPN-OneClick need before it will install?
A Linux server with a public IP address, 512 MB of RAM as the stated floor, and Ubuntu 22.04 or newer, Debian 11 or newer or CentOS 9 or newer. The detailed requirements table also lists Kali 2023 or newer, and Fedora 39 or Amazon Linux 2023, and recommends Ubuntu 22.04 LTS or Debian 12 with 1 GB of RAM and 10 Mbps of bandwidth.
Do I need to buy a domain for VLESS plus Reality?
No. The protocol section states that no domain purchase and no certificate configuration are required, and the system requirements never mention a domain name. What is required is a public IP address on the server.
How do I install Xray-VPN-OneClick with npm?
Install the global package and then run the installer through its short binary name, with Node.js 18 or newer available first. The package registers both xray-manager and xm as names for the same compiled entry point, and the script runs under sudo because it installs a systemd service.
Does the subscription service support Clash?
The client feature list says the built-in subscription service uses a standard format and supports V2RayN and Clash, and the file recommends Clash Verge Rev as the Clash client. The same section lists automatic client updates and QR codes for quick import.
Is Xray-VPN-OneClick available in English?
The top-level README is Chinese and links an English version filed under docs, with a language switcher near the top. Everything else in the repository, including the configuration examples, the security policy and the contribution guide, sits beside the Chinese file without a stated translation.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/danops-1-xray-vpn-oneclick)