ProxyDroid: a VPN-first global proxy for Android without root
Global Proxy for Android
At a glance
- What is it?
- ProxyDroid routes Android device traffic to an upstream SOCKS5 or HTTP proxy by running as a VpnService, with a Rust tun2socks bridge built through JNI. Here is what the repository shows about building it, using it, and where it falls short.
- Who is it for?
- ProxyDroid fits Android users who need whole-device SOCKS5 or HTTP proxying without root and are willing to build from source, since the README documents only Gradle build paths. Users who need a signed APK from a store listing, a maintained binary channel, or a proxy protocol beyond SOCKS5 and HTTP CONNECT should not adopt it yet.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 143 days ago.
- What is it written in?
- Mainly Kotlin, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What problem ProxyDroid solves, and for whom
Android has no system-wide proxy setting that applies to every app. Per-network Wi-Fi proxies exist in the platform settings, but they do not cover mobile data, and they do not cover apps that ignore the system proxy. ProxyDroid takes a different route: it registers a VpnService, captures IP packets on a TUN device, and converts TCP and UDP flows into connections to an upstream SOCKS5 or HTTP proxy. The README states the app forwards device traffic "without requiring root", which is the main distinction from the older iptables and redsocks approach the project used previously.
The intended audience is an Android user or developer who controls an upstream SOCKS5 or HTTP proxy and wants all device traffic to pass through it. Because the app runs as a standard VpnService, it works on every supported Android release according to the README, and the minimum is minSdk 24 (Android 7.0). It is not a consumer VPN client with a subscription backend, and it does not provide proxy servers of its own. You bring the upstream.
The VpnService and Rust tun2socks mechanism
The architecture has three layers. The Android side is a VpnService that captures IP packets on a TUN device. The packet-to-socket bridge lives in a Rust crate at app/src/main/rust/proxydroid-tun2socks, built on the netstack-smoltcp crate and invoked from Kotlin through JNI. Cargo builds are wired into Gradle through org.mozilla.rust-android-gradle. The settings and status screens are Jetpack Compose with Material 3.
That split matters for anyone reading the source. The Kotlin layer owns the VpnService lifecycle, the UI, and the per-app bypass list, while the Rust crate owns the TCP/IP stack and the translation of flows into proxy connections. The README notes that legacy cpp/libevent and cpp/redsocks directories from the iptables era are scheduled for removal and that "the redsocks path is no longer reachable from Kotlin". In other words, the old native path is dead code waiting to be deleted, not a fallback you can enable.
Supported upstreams are limited to SOCKS5 with optional username and password authentication, and HTTP CONNECT with optional Basic auth. Per-app bypass uses the standard VpnService addDisallowedApplication API, so excluding an app is a platform feature rather than a custom hook. Supported ABIs are armeabi-v7a, arm64-v8a, x86 and x86_64.
Building ProxyDroid from source on the command line
The README gives prerequisites rather than a download link. You need JDK 17, because Gradle 8.x does not accept JDK 21 or newer. You also need the Android SDK with compileSdk 36, Android NDK 25.1.8937393, CMake 3.22.1, and a Rust stable toolchain with four Android targets: aarch64-linux-android, armv7-linux-androideabi, i686-linux-android and x86_64-linux-android. AGP is pinned to 8.1.2 and Kotlin to 1.9.10, with gradle/libs.versions.toml as the single source of truth. The README warns against bumping AGP without checking the rust-android-gradle 0.9.6 mergeJniLibFolders duplicate-resources interaction.
Add the Rust targets first, then build the debug APK:
rustup target add aarch64-linux-android armv7-linux-androideabi \
i686-linux-android x86_64-linux-android
./gradlew assembleDebugThe debug APK lands at app/build/outputs/apk/debug/. Cargo runs as part of cargoBuild and feeds the JNI libraries into the merged APK, so a missing Rust target fails the build rather than producing an APK without native code.
Release builds are opt-in for signing. Create a local.properties with the keystore values:
KEYSTORE_PATH=/absolute/path/to/keystore.jks
KEYSTORE_PASSWORD=...
KEY_ALIAS=...
KEY_PASSWORD=...If those keys are absent, the README states the release variant builds unsigned. That is a real deployment constraint: an unsigned release APK will not install as an update over an existing installation.
For a first real test, the repository ships an integration test that routes an HTTP request through a SOCKS5 proxy on the host. Start the stdlib-only Python proxy, then run the instrumentation test on a booted emulator:
python3 scripts/socks5_test_server.py --host 0.0.0.0 --port 1080
./gradlew connectedAndroidTest \
-Pandroid.testInstrumentationRunnerArguments.class=org.proxydroid.HostSocks5ProxyIntegrationTestThe emulator reaches host loopback through the alias 10.0.2.2, so a proxy bound to 0.0.0.0:1080 appears to the device as 10.0.2.2:1080. Defaults can be overridden with socksHost, socksPort, targetHost and targetPort.
Where ProxyDroid is the wrong tool
The upstream protocol list is the first limitation. SOCKS5 and HTTP CONNECT cover a lot of ground, but a user with a Shadowsocks, WireGuard or Trojan endpoint cannot point ProxyDroid at it directly. The README documents no plugin interface and no protocol beyond those two, so bridging to another protocol requires a local converter on the device or a relay elsewhere.
Android itself imposes the second limit. Only one VpnService can be active at a time on a device, so ProxyDroid cannot run alongside another VPN app. That is a platform rule, not a ProxyDroid bug, but it decides the use case: this is the tunnel or it is nothing.
The third issue is distribution. The homepage listed for the repository is a Google Play URL, but the README documents no store installation path and no prebuilt APK download. Everything in the build section starts from the project root with Gradle. For a user who wants a signed binary and no toolchain, the repository as it stands does not answer that need. The LICENSE section says GPLv3, which also affects redistribution: anyone shipping a modified APK carries the corresponding source obligations, and this article does not give legal advice on what that means for a specific product.
ProxyDroid compared with a per-app proxy client
The obvious alternative approach is an app that proxies only selected apps through a local SOCKS or HTTP listener, leaving the rest of the device on the normal network path. ProxyDroid inverts that: it is global by default and offers per-app bypass through addDisallowedApplication, so the exclusion list is the exception rather than the rule. If your goal is to send one browser through a proxy and leave everything else alone, a per-app client expresses that directly, while ProxyDroid asks you to enumerate everything you want to keep outside the tunnel.
The second alternative is the legacy root approach the project itself abandoned: iptables rules plus a redsocks-style redirector. That path can work on rooted devices and can cover traffic in ways a VpnService cannot, but it requires root, it is fragile across Android releases, and ProxyDroid's own README describes the redsocks code as unreachable from Kotlin and scheduled for removal. Choosing that route today means maintaining a path the upstream project is deleting.
A third comparison is a full VPN client. Those typically ship their own server infrastructure and a signed app, which removes the build step entirely, but they also mean you do not control the upstream proxy. ProxyDroid assumes you already have one.
Maintenance status and upgrade cost
The repository is not archived, and the last push was on 2026-05-12. The most recent release listed is v3.4.0, published on 2026-02-06. That is the extent of what the repository metadata shows; the README does not publish a support policy, a release cadence, or a deprecation timeline for the legacy native directories.
Upgrade cost is dominated by the pinned toolchain. JDK 17 is a hard ceiling for the current Gradle setup, and the README explicitly warns that Gradle 8.x rejects JDK 21 and newer. AGP 8.1.2 and Kotlin 1.9.10 are pinned, and the README ties AGP upgrades to verifying the rust-android-gradle mergeJniLibFolders duplicate-resources interaction, referencing commits 0249f91 and 8875c74. In practice that means moving any of these versions is a coordinated change across Gradle, AGP, the Rust plugin and the native build, not a version bump in one file.
Licensing: the README states GPLv3. Anyone who modifies and redistributes the app should read the licence text themselves, because the obligations attach to distribution, not to private builds. Nothing in the repository suggests a separate commercial licence.
Editorial conclusion
ProxyDroid fits Android users who need whole-device SOCKS5 or HTTP proxying without root and are willing to build from source, since the README documents only Gradle build paths. Users who need a signed APK from a store listing, a maintained binary channel, or a proxy protocol beyond SOCKS5 and HTTP CONNECT should not adopt it yet. Before committing, verify that your toolchain matches JDK 17, NDK 25.1.8937393, CMake 3.22.1 and compileSdk 36, and check whether the release variant is signed by your own local.properties keystore, because unsigned release builds will not install over an existing app.
Frequently asked questions
What is ProxyDroid on Android?
It is a global proxy app that forwards device traffic to an upstream SOCKS5 or HTTP proxy. It installs a VpnService, captures IP packets on a TUN device, and converts TCP and UDP flows into proxy connections in userspace, without requiring root.
How do I use ProxyDroid?
The README documents building it from source rather than a store install: set up JDK 17, the Android SDK with compileSdk 36, NDK 25.1.8937393, CMake 3.22.1 and the four Rust Android targets, then run ./gradlew assembleDebug. The debug APK is written to app/build/outputs/apk/debug/.
Is ProxyDroid safe?
The repository does not publish a security audit or a threat model, so safety cannot be confirmed from what the project documents. What can be checked is the mechanism: it runs as a standard Android VpnService and supports SOCKS5 with optional username and password auth and HTTP CONNECT with optional Basic auth, so the upstream proxy you configure is the party that sees your traffic.
What is a ProxyDroid alternative for Android?
A per-app proxy client is the closest alternative in approach: it proxies only the apps you select through a local listener instead of tunnelling the whole device. ProxyDroid is global by default and uses the VpnService addDisallowedApplication API for per-app bypass, so the two designs ask you to manage opposite lists.
What does proxy mean on my phone?
In this context a proxy is an intermediary server that your device sends traffic through, and ProxyDroid forwards Android traffic to an upstream SOCKS5 or HTTP proxy. The app itself does not provide that server; you supply the upstream endpoint.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/madeye-proxydroid)