Anywhere: a native Swift proxy client for iPhone, iPad and Apple TV
The best native proxy client for iOS, iPadOS, macOS, and tvOS.
At a glance
- What is it?
- Anywhere implements its proxy protocols, TLS and QUIC stacks directly in Swift and C instead of bridging a Go core. Here is how the packet tunnel is wired, what the repository ships, and where the approach runs into trouble.
- Who is it for?
- Anywhere is worth adopting if you need a proxy client whose protocol stack you can read and modify in Swift, and you accept building it from an Xcode project under GPL-3.0. It is the wrong choice if you want a maintained App Store binary with release notes, or if your config lives in a sing-box or Xray profile you are unwilling to convert.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly Swift, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem Anywhere is aimed at, and who feels it
Most iOS proxy clients are wrappers. The README states the common pattern plainly: a sing-box or Xray-core binary compiled from Go or C++, bridged into a Swift app through a foreign-function layer. That bridge costs memory, adds a translation step between the app and the tunnel, and puts the interesting code in a language the iOS developer cannot read.
Anywhere rejects that. The README describes it as "a native, zero-dependency proxy client built entirely in Swift," with no Electron, no WebView and no sing-box wrapper. The audience is narrow and specific: an engineer or power user who runs their own proxy server, wants a client on Apple hardware, and would rather audit Swift than trust a prebuilt core. If you just want a VPN toggle on your phone, this is a lot of machinery for the job.
How the packet tunnel is wired: lwIP, five-tier routing, and an actor-bound stack
The architecture diagram in the README shows two processes. The app side holds SwiftUI views, SwiftData stores with CloudKit sync, and an operations layer that compiles routing and MITM payloads. It hands work to the Network Extension over provider messages, App Group files and Darwin notifications, and receives stats, requests and logs back.
Inside the extension, PacketTunnelProvider drives TunnelStack, which the README describes as a userspace lwIP TCP/IP implementation. Three paths leave the stack: DNS through a Fake-IP pool, TCP through a connection object that sniffs SNI and HTTP, and UDP through a plane that handles QUIC and WebRTC policy. All three feed ConnectionRouter, a five-tier matcher built from domain-suffix tries, keyword automata and CIDR tries. The router returns one of three verdicts: reject, direct, or proxy with chain hops.
Two details in that diagram are worth pausing on. First, classification happens at three separate moments: at DNS time through Fake-IP, at connect time before the TCP handshake is accepted, and again mid-connection from the sniffed TLS SNI. That is more invasive than a single hostname lookup, and it is what makes rules like "route by the SNI actually presented" possible. Second, the README states that the tunnel stack, TCP connections and MITM sessions are actors bound to the lwIP serial executor, so the packet path never changes threads. That is a deliberate answer to a real problem in Swift concurrency, where hopping between executors under packet load is expensive.
Building Anywhere from the Xcode project
There are no release artifacts in the repository and the README points readers to the App Store listing rather than to a build guide. What the repository does contain is Anywhere.xcodeproj at the top level, alongside target folders for the network extension, the TV app, the watch app, widgets, shared code and tests. That layout implies the normal Xcode flow.
Clone the repository and open the project:
git clone https://github.com/NodePassProject/Anywhere.git
cd Anywhere
open Anywhere.xcodeprojFrom there you select an iOS target and run it on a device or simulator. The README does not document signing, provisioning, or which Xcode and Swift versions are required beyond the Swift 6 reference in the feature list, so treat those as things you will discover during the first build rather than steps the project walks you through.
Once running, the app side is where configuration begins. The README describes an operations layer that compiles routing and MITM payloads and passes them to the extension, and it mentions importable and subscribable `.arrs` rule sets. The developer guide for authoring those sets lives in Documentations/Routing.md, which the README links as the routing rule system reference. That file is the place to look before writing rules by hand.
The protocol table is the real feature list, and it is uneven
Anywhere supports Nowhere, VLESS, Hysteria2, Sudoku, Trojan, AnyTLS, Shadowsocks, SOCKS5 and plain HTTP CONNECT. The depth varies a great deal between them.
VLESS gets the longest entry: post-quantum `mlkem768x25519plus` encryption with 0-RTT, XTLS-RPRX-Vision, Reality with browser fingerprints, four transports including XHTTP over HTTP/1.1, HTTP/2 and HTTP/3, upload and download detach, XMUX pooling and XUDP. Shadowsocks covers the 2022 variant with BLAKE3 key derivation and replay protection alongside classic AEAD ciphers. Hysteria2 sits on the QUIC stack with Brutal congestion control and two obfuscation schemes.
Sudoku is the outlier. Its README entry describes payloads encoded as Sudoku-grid hints with per-direction ASCII or entropy layouts and randomly selected custom tables, a KIP X25519 handshake with session rekeying, and HTTP masquerade in four modes. That is an unusual design, and it is also the protocol least likely to have a second client you can fall back to. If you build a deployment around Sudoku, Anywhere is effectively your only client on this platform. Trojan and AnyTLS are comparatively thin entries, which is fine for Trojan and less reassuring for AnyTLS, whose server-driven padding scheme and warm TLS session pool imply a server component that has to cooperate.
The Network Extension memory budget shapes the whole design
The README devotes a bullet to what it calls the extension budget: global buffer ledgers, connection caps and pressure throttling to keep the packet tunnel inside the Network Extension memory limit. This is the constraint that explains several other choices, including the userspace lwIP stack and the actor binding.
It is also the most likely failure mode in practice. A proxy client on iOS does not get to allocate freely; when the extension exceeds its allowance the system kills it, and the user sees the tunnel drop. Anywhere's answer is to cap connections and throttle under pressure, which means that under heavy load the client will refuse or slow new flows rather than degrade gracefully. The README does not state the specific limit or the cap values. If you run many concurrent connections, that behaviour is what you will hit first, and it is not configurable in anything the README documents.
Anywhere against a sing-box or Xray wrapper client
The obvious alternative is any client that wraps sing-box or Xray-core, which is what the README says most iOS proxy clients do. The difference is not cosmetic.
With a wrapper client, protocol support arrives when the upstream core adds it. You get a large, widely tested protocol matrix and a configuration format that other tools also read, so a profile written for a desktop client often works unchanged. The cost is a Go or C++ binary inside your app, a bridging layer, and a memory profile that Anywhere's README explicitly positions itself against.
With Anywhere, protocol behaviour is Swift and C you can read, the TLS stack is shared between client and server roles, and the same code builds the iOS, iPadOS, tvOS and watchOS apps plus the packet tunnel and Control Center controls. The cost is that you depend on this one repository for everything: a bug in the native TLS stack is a bug in every protocol at once, and there is no upstream project to inherit fixes from. There are also no releases in the repository, so the App Store listing is the only distribution channel the README names.
Licence, maintenance and what an upgrade actually costs
Anywhere is GPL-3.0. For a client you install on your own devices this changes little. For anyone considering shipping a modified build, the copyleft terms apply to the whole work, and the repository contains no separate licensing note that would soften that. This is not legal advice; read the LICENSE file.
The repository is not archived, and the last push was on 2026-09-14, which is recent. There are no retrieved releases, so upgrades are not something you pull from a changelog. You rebuild from the default branch. That has a concrete consequence: there is no version to pin, no release notes to read before upgrading, and no documented rollback path. The README does not document rollback. If you depend on a specific behaviour, record the commit you built from, because the next build may differ without any announcement you can subscribe to.
Editorial conclusion
Anywhere is worth adopting if you need a proxy client whose protocol stack you can read and modify in Swift, and you accept building it from an Xcode project under GPL-3.0. It is the wrong choice if you want a maintained App Store binary with release notes, or if your config lives in a sing-box or Xray profile you are unwilling to convert. Before committing, verify three things in the repository: whether the protocol you depend on appears in the README protocol table, whether Documentations/Routing.md covers the rule set format you need, and whether Anywhere.xcodeproj builds against the Xcode version you have installed.
Frequently asked questions
How do I install Anywhere on a Mac or iPhone?
The README links to an App Store listing for the iOS, iPadOS and tvOS apps. The repository itself ships no releases, so building from Anywhere.xcodeproj is the alternative path, and the README does not document the build steps.
Does Anywhere use sing-box or Xray-core?
No. The README states that every protocol, transport, the QUIC stack and the packet tunnel are implemented natively in Swift and C, with no Go or C++ core and no bridging layer. It vendors C for lwIP, ngtcp2 and BLAKE3.
Which proxy protocols does Anywhere support?
The README lists Nowhere, VLESS, Hysteria2, Sudoku, Trojan, AnyTLS, Shadowsocks, SOCKS5 and HTTP CONNECT over HTTP/1.1 or HTTP/2. Support depth varies: VLESS and Shadowsocks have the longest entries, while Trojan and AnyTLS are described briefly.
What licence is Anywhere released under?
GPL-3.0, per the repository's LICENSE file. The README gives no additional licensing terms.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/nodepassproject-anywhere)