Orbot: Tor on Android, Built as a VPN Service Other Apps Can Use
The Github home of Orbot: Tor on Android (Also available on gitlab!)
At a glance
- What is it?
- Orbot routes Android app traffic through Tor by presenting itself as a VPN. Here is how the pieces fit, how to build it, and where it stops being the right tool.
- Who is it for?
- Orbot fits Android users who need app-level traffic routed through Tor and are willing to accept slower connections, plus developers who want to build the APK from source. It is the wrong choice if you need to hide the fact that you are using Tor, or if you only want a conventional VPN that changes your apparent location.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 3 days ago.
- What is it written in?
- Mainly Kotlin, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem Orbot solves on Android
On a desktop, running Tor is a matter of starting a proxy and pointing a browser at it. On Android that model breaks down. Most apps have no proxy setting, and the ones that do rarely expose it in a way a user can configure. Orbot's answer is to look like a VPN. Android lets a single app take over the device's network stack through the VpnService API, and Orbot uses that position to intercept traffic and hand it to Tor instead of sending it out over the normal connection. The README describes it plainly: Orbot is a free VPN and proxy app that lets other apps use the internet more securely, encrypting traffic and bouncing it through a series of computers around the world.
The audience named in the README is specific: human rights activists, journalists, and others in the Guardian Project's orbit who need a secure and anonymous smartphone. That framing matters when you judge the app. Orbot is not trying to be a general consumer VPN with a server picker and a streaming-unblock pitch. It is trying to make Tor usable on a platform that was not designed for it.
How the VPN mode, the Tor process and app selection fit together
Two architectural details in the README shape everything else. The first is that Tor runs as its own Linux process on Android rather than inside the primary app process. The README notes this was a recent change and warns that tor, OrbotService and OrbotVPNManager logs will no longer appear in Android Studio as a result. That is not just a logging inconvenience. It means the Tor daemon has a separate process identity, which is why the log commands later in the README target two different process names.
The second is the native dependency. Orbot is built with hev-socks5-tunnel, a C component cloned as a git submodule at app/src/main/jni/hev-socks5-tunnel. The name tells you the shape of the data flow: a SOCKS5 tunnel. Traffic captured by the VPN interface is fed into a SOCKS5 path that terminates at Tor, and the tunnel library is what moves packets between the Android VPN file descriptor and that SOCKS5 endpoint. Gradle builds the C code; you do not compile it by hand.
On top of that sits app selection. The README's screenshots include a screen literally titled Choose Apps, which is the user-facing control over which applications are routed through the tunnel. The README does not document the per-app routing internals beyond that screen, so treat the selection UI as the documented surface and nothing more.
Building Orbot from source and running the unit tests
The README gives one supported path to a build, and it starts with the submodule. Cloning without --recursive leaves you without the hev-socks5-tunnel C code, and the build will not produce a working tunnel.
git clone --recursive https://github.com/guardianproject/orbot-android
cd orbot-android
./gradlew assembleFullpermDebugIf you already have the repository, the README's recovery path is a pull followed by a submodule update:
cd orbot-android
git pull
git submodule update --init --recursive
./gradlew assembleFullpermDebugThe README also flags a recurring failure mode. If you pull new commits and git reports changes under app/src/main/jni/hev-socks5-tunnel, the pinned version of the tunnel library has moved. Run the submodule update again and check that git status is clean, which is the signal the README gives that you are back in sync.
Unit tests exist, and the README is candid about their scope: they cover bridge parsing. New features are expected to come with tests. The command is:
./gradlew :app:testFullpermDebugUnitTestFinally, because Tor is a separate process, debugging means two log streams. The README supplies a tmux helper that prints them side by side:
./scripts/view_logs_tmux.shThat script needs tmux installed and adb on your PATH. The README gives brew install tmux for macOS, sudo apt intstall tmux for Debian and friends (the typo is in the README), and an ANDROID_HOME export plus platform-tools path entry for the SDK.
Where Orbot is the wrong tool
The most important limitation is not a bug. Tor is designed so that observers cannot easily tell what you are doing inside the network, but the use of Tor itself is often detectable, and Orbot does nothing to change that. If your threat model includes an adversary who blocks or penalizes Tor traffic on sight, a Tor client on your phone is the wrong instrument regardless of how well it is built. The README points readers at the Tor Project's own usage instructions and FAQ for this reason.
There is a second, more mundane boundary. Orbot is an Android app, full stop. The repository is Kotlin with a Gradle build and an Android VpnService dependency, and the release tags are Android app versions paired with Tor versions. If you need Tor on a server, a router or a desktop, this project has nothing to offer you.
The README is also thin in places that matter for operations. It documents bridge parsing tests but does not describe bridge configuration in the README body. It does not document rollback if a beta or release candidate misbehaves, and the release list shows the project does ship BETA and RC builds, so that gap is real rather than hypothetical. Anyone running those builds is doing so without a documented recovery path from the README alone.
Orbot against a conventional Android VPN
The obvious alternative is an ordinary commercial VPN client, and the difference is not speed. A conventional VPN gives you one encrypted hop to a provider's server, and that provider can see your traffic and knows who you are. Its goal is to change your apparent location and to keep your traffic away from the local network. Orbot's goal is different: it hides the connection between your internet address and the services you use by bouncing traffic through a series of relays, so no single relay holds both ends of the picture.
That distinction produces different costs. A commercial VPN is usually fast because it is one hop. Orbot is slower because it is several, and because Tor relay capacity is not provisioned for streaming. It also produces a different trust story: with a commercial VPN you are trusting a company, while with Tor you are trusting the protocol design and the diversity of the relay set. Neither is free, but they are not the same purchase, and picking Orbot because it is labeled a VPN will lead to disappointment on the first video call.
Maintenance, upgrades and the licence question
The repository is not archived. The last push was on 2026-09-22, one day before the date used here, and the most recent release is 17.9.6-BETA-1-tor-0.4.9.12 from 2026-09-18. Two release candidates for 17.9.5 shipped in July 2026 against tor 0.4.9.11. So the project is shipping, and the release tags tie each app version to a specific Tor version, which is the thing to read first when you decide whether to upgrade.
Upgrade cost lands mostly on builders. Every time the pinned hev-socks5-tunnel revision changes, you rerun git submodule update --init --recursive and rebuild, and the README expects you to notice the change through git status. There is also a version catalog check for Android dependency updates:
./gradlew versionCatalogUpdate --checkOn licensing, the repository metadata reports NOASSERTION, which means GitHub could not map the LICENSE file to a recognized identifier. The LICENSE file is present at the top level. Read it yourself before you redistribute a build; nothing in the README states the terms, and this is not a question anyone else can answer for you.
Editorial conclusion
Orbot fits Android users who need app-level traffic routed through Tor and are willing to accept slower connections, plus developers who want to build the APK from source. It is the wrong choice if you need to hide the fact that you are using Tor, or if you only want a conventional VPN that changes your apparent location. Before adopting it, verify the submodule state with git submodule update --init --recursive, and confirm the Tor version in the release tag you plan to install.
Frequently asked questions
Can Orbot be tracked?
The README does not make a claim either way about detecting Orbot itself; it points readers to the Tor Project's usage instructions and FAQ, and states that Tor is believed to be reasonably secure but should be configured properly. Tor hides the connection between your address and the services you use, which is a different question from whether the use of Tor is visible on the network.
Is Orbot removed from the Play Store?
The README links to the Play Store listing at play.google.com/store/apps/details?id=org.torproject.android, and it also links to the latest release on GitHub. Nothing in the README says the Play Store listing was removed.
How to use Orbot on Android?
Install the app, start the connection, and use the Choose Apps screen shown in the README's screenshots to decide which applications are routed through the tunnel. Orbot presents itself as a VPN, so Android will ask you to grant that permission when you enable it.
Is Orbot just a VPN?
No. The README describes Orbot as a free VPN and proxy app, but the traffic it carries is routed through Tor, encrypting it and bouncing it through a series of computers around the world rather than sending it to a single provider's server.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/guardianproject-orbot-android)