Se7en Pro: a Windows anti-censorship client that chains Psiphon, Tor and WARP
Modern Multi-Engine Windows Client & Anti-Censorship Suite
At a glance
- What is it?
- Se7en Pro is a Flutter front end over a .NET 8 daemon that orchestrates Psiphon, Tor, MASQUE/WireGuard, Xray and sing-box on Windows. It is a clean framework, not a subscription: you bring the Psiphon sponsor values and the server configs.
- Who is it for?
- Adopt Se7en Pro if you run Windows 10 or 11, you already have Psiphon sponsor values or Xray/sing-box outbound configs, and you want chained tunnels such as Psiphon over WARP without assembling tun2socks, wintun and a Tor daemon yourself. Do not adopt it if you expect a client that connects out of the box with a bundled server list, or if you need macOS, Linux or Android; the README names only Windows 10 and 11 on x86 and x64.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 15 days ago.
- What is it written in?
- Mainly Dart, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Se7en Pro is for, and who it is not for
Se7en Pro targets one narrow problem: assembling several circumvention engines on Windows without writing the glue yourself. The README describes it as an orchestrator that aggregates Cloudflare MASQUE, TLS ClientHello fragmentation, Psiphon, Tor and V2Ray/Xray/Sing-box chained transports into one desktop client with a single TUN interface. The intended user is someone who already knows what a sponsor ID or a VLESS outbound is, and who is tired of running four separate tools that each install their own network adapter.
The repository is deliberately not a consumer VPN. The README states that it does not hardcode private tokens, proprietary server lists or sponsor configs, and that you supply your own values or use the public multi-protocol engines out of the box. That sentence is the whole adoption decision. If what you want is a client that installs and connects to somebody else's infrastructure, this is the wrong project. If what you want is the orchestration layer and you have the endpoints, it is a reasonable fit.
Two smaller constraints follow from the same design. The client is Windows-only: the badge and the build requirements name Windows 10 and 11 on x86 and x64, and nothing in the repository structure suggests a portable core. And the interface is localized in English, Russian and Chinese, so a user outside those three languages reads the UI in a second language.
How the Flutter GUI talks to the Se7enCore daemon
The architecture diagram in the README shows two layers. On top sits the Se7en Flutter GUI, which handles glassmorphic controls, telemetry and routing. Below it sits Se7enCore, a .NET 8 headless background daemon that acts as the process controller. The two communicate over named pipes IPC, which is the standard Windows mechanism for local process-to-process messaging and avoids opening a TCP port on the loopback interface.
Under the daemon the diagram lists four engine slots: Aether for MASQUE v2 and WireGuard, Psiphon for TunnelCore, Tor for onion mesh, and SHARD for fragmentation and subnode work. That split matters operationally. The GUI is a Flutter build, so it is compiled separately from the daemon, and the daemon is a .NET build with its own runtime identifier. A bug in one half does not necessarily implicate the other, and a rebuild of one does not require rebuilding the other.
Packet capture happens below both, through wintun.dll and tun2socks, which the README describes as kernel-level TUN routing with zero DNS leaks. Split tunneling is offered at two levels: by application, and by domain through split-aware DNS interception with whitelist and blacklist rules. A kill switch is listed to prevent IP leakage on unexpected termination. None of these are unusual choices for a Windows tunnel client, but the combination under one GUI is the point of the project.
Building Se7en Pro from source on Windows
The README does not publish a signed installer. It documents a build from source, and the requirements are specific: Windows 10 or 11, the .NET SDK 8.0, a Flutter SDK of version 3.x or newer, and Visual Studio 2026 or later with the Desktop development with C++ workload. That last item is easy to miss and the Flutter Windows build fails without it.
Build the daemon first. From the repository root, the README gives this sequence:
cd Se7enPro
dotnet build -c Release -r win-x64 --self-contained falseThe runtime identifier is win-x64 and the build is framework-dependent, so the target machine needs the .NET 8 runtime installed rather than carrying it inside the output.
Then build the client. The Flutter project lives in Se7enFlutter and needs its packages resolved before the Windows target compiles:
cd ../Se7enFlutter
flutter pub get
flutter build windows --releaseBefore any of this will connect, the README says to open Se7enPro/Services/EmbeddedValues.cs and replace the placeholder constants with your network configuration. The two named in the README are the propagation channel ID and the sponsor ID:
public const string PropagationChannelId = "YOUR_PROPAGATION_CHANNEL_ID";
public const string SponsorId = "YOUR_SPONSOR_ID";The same file holds public keys, fronted URL lists and feedback endpoints that the README leaves as comments. Leaving the placeholders in place is the most likely reason a first run produces no tunnel. The README also mentions an optional plaintext server_entries.txt placed in Se7enPro/Resources/ for offline server caching.
Chained tunnels and the SHARD inheritance from MSN-GUARD
The feature that distinguishes Se7en Pro from a protocol switcher is chaining. The README lists four combinations: Psiphon over WARP, Tor over WARP, Psiphon over V2Ray, and Tor over V2Ray. Each means one transport carries another, so the outer hop sees only the inner protocol's traffic and the exit is not the entry. That is a different model from a client that lets you pick one engine at a time.
The README credits the chained transport architecture and the SHARD fragmentation method to the Android project MSN-GUARD by mbm110. SHARD is described as TLS ClientHello fragmentation plus IP-level packet shredding to defeat deep packet inspection, with automatic node pool discovery. The credit is explicit, and it is worth reading as a signal about maturity: the technique was developed elsewhere and ported, not invented here.
Chaining has a cost the README does not quantify. Two hops mean two handshakes, two points of failure and roughly double the latency of the faster leg. The README does not publish throughput or latency figures for any chain, so treat the combinations as available rather than as free. If your use case is bulk transfer, a single WARP or WireGuard tunnel will almost certainly beat Psiphon over WARP.
The limitations the README states, and the one it does not
The clearest limitation is stated up front: no bundled credentials, no server list, no sponsor configs. A user who clones the repository and builds it gets a working GUI attached to engines that have nothing to dial. The README's own fix is to edit EmbeddedValues.cs, which assumes you have Psiphon sponsor values in the first place. Those are not distributed with the project and the README does not say where to obtain them.
The second limitation is platform. Windows 10 and 11 on x86 and x64 only. No macOS build, no Linux build, no Android build appears in the repository layout or the build instructions. If your team is mixed-platform, this client covers a subset of it and you will still need something else for the rest.
The third is the toolchain. A Flutter SDK, a .NET 8 SDK and a C++ workload in Visual Studio is a heavier prerequisite than downloading an executable, and the README documents no CI-produced artifact. There is also no rollback or uninstall procedure documented: the README does not describe how to remove the Wintun adapter or the kill switch rules after an uninstall. That is a real gap for anyone deploying on a machine they do not own.
How Se7en Pro differs from Hiddify and from running the engines directly
Hiddify is the closest well-known alternative, and the difference is in what each one is. Hiddify is a cross-platform client built around the sing-box core, with a subscription model: you paste a subscription link or a config and it connects. Se7en Pro is Windows-only and organizes several engines, including sing-box and Xray as inbound engines for VLESS, VMess, Trojan and Shadowsocks, under a daemon that also drives Psiphon and Tor. If your workflow is subscription links on several operating systems, Hiddify covers more ground with less setup. If your workflow is chaining Psiphon or Tor behind WARP on Windows, Se7en Pro is doing work Hiddify does not describe.
The second alternative is assembling the pieces yourself: psiphon-tunnel-core, tor.exe and tun2socks are all separately available, and Se7en Pro bundles them. Running them by hand gives you full control over versions and arguments, and no dependency on a GUI. What you lose is the named-pipe daemon, the split-tunneling rules, the kill switch and the telemetry console, all of which you would have to build or script. That trade is worth making if you need one engine and nothing else.
Licence position and the upgrade cost of a fast release cadence
The source code in the repository is MIT-licensed. The bundled binaries are not, and the README's table is explicit: psiphon-tunnel-core.exe and tun2socks.exe are GPLv3, wintun.dll is GPLv2, and tor.exe with the geoip files is BSD-3-Clause. The README's table is truncated at the lyrebird and conjure entries, so check Resources/ in the repository for the full set before you redistribute anything. Mixing MIT source with GPLv3 executables is common in this space, but if you ship a modified build to third parties the GPL obligations attach to those binaries. That is a question for a lawyer, not for this article.
Upgrade cost is driven by upstream churn rather than by this project. Psiphon, Tor, Xray and sing-box all release on their own schedules, and each bundled binary has to be refreshed to pick up fixes. The release history shows three tagged versions in about two weeks, v1.0.2 and v1.0.3 on 2026-08-30 and v1.0.4 on 2026-09-14, with the last push on 2026-09-14. A cadence that fast means fixes arrive quickly and also that pinning to a specific tag, rather than tracking master, is the safer choice for a machine you depend on.
Editorial conclusion
Adopt Se7en Pro if you run Windows 10 or 11, you already have Psiphon sponsor values or Xray/sing-box outbound configs, and you want chained tunnels such as Psiphon over WARP without assembling tun2socks, wintun and a Tor daemon yourself. Do not adopt it if you expect a client that connects out of the box with a bundled server list, or if you need macOS, Linux or Android; the README names only Windows 10 and 11 on x86 and x64. Before you build, verify three things: that your Visual Studio install includes the Desktop development with C++ workload, that you have replaced the placeholder constants in Se7enPro/Services/EmbeddedValues.cs, and that you are comfortable redistributing the GPLv3 psiphon-tunnel-core.exe and tun2socks.exe binaries that sit under Resources/ next to MIT-licensed source.
Frequently asked questions
Is Se7en Pro a free VPN with its own servers?
No. The README states that the repository does not hardcode private tokens, proprietary server lists or sponsor configs, so there is no bundled infrastructure to connect to. You supply Psiphon values or your own VLESS, VMess, Trojan or Shadowsocks configurations.
Which Windows versions can run the Se7en Pro client?
The README lists Windows 10 and 11 on x86 and x64, and the build instructions target the win-x64 runtime identifier. No macOS, Linux or Android build appears in the repository layout or the build steps.
Why does Se7en Pro not connect after I build it?
The README instructs you to open Se7enPro/Services/EmbeddedValues.cs and replace the placeholder constants, including the propagation channel ID and the sponsor ID, with your own network configuration. Leaving those placeholders in place is the most likely reason a first run produces no tunnel.
What licence applies to the bundled psiphon-tunnel-core.exe and tun2socks.exe?
The README's licence table lists both as GPLv3, while wintun.dll is GPLv2 and tor.exe with the geoip files is BSD-3-Clause. Only the source code in the repository is MIT-licensed.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/kng7-p-se7en-pro)