Library / SDK
ProtonVPN/android-app avatar
ProtonVPN/android-app

ProtonVPN for Android: building the official client from source

Official ProtonVPN Android app

4,124 stars507 forksKotlinGPL-3.0

At a glance

What is it?
ProtonVPN's Android client is a GPLv3 Kotlin and Java app with published build instructions and a signed release key. Here is what it takes to build it, what the codebase assumes, and where the open source build stops.
Who is it for?
Adopt this repository if you want the official ProtonVPN Android client under GPLv3, if you need to inspect or rebuild it, or if you are contributing Kotlin in the MVVM style the README asks for. Do not adopt it if you are looking for a library to embed in your own VPN product, if you need a documented server API, or if you expect the open source build to match the Play Store build exactly.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Kotlin, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the ProtonVPN Android client actually is

This is the official ProtonVPN application for Android, published by Proton AG and licensed under GPLv3. It is an end-user VPN client, not a library and not a server. The repository topics list ikev2, openvpn and strongswan alongside android, kotlin and java, which tells you the app is a front end over several tunneling implementations rather than a single protocol stack. The README is explicit that the code base is mostly written in Java and is transitioning to Kotlin, with new code expected in Kotlin where possible.

The audience is narrow in a useful way. If you are a ProtonVPN user who wants a build you can reproduce, or a developer who wants to contribute to a large production Android codebase, this is the right repository. If you want to understand how ProtonVPN's backend works, the README does not describe it. The protocol names in the topics are the only hint about what sits underneath the UI.

How the app is put together, as far as the repository shows

The top level of the repository separates the application from its build and quality tooling. app/ holds the Android module. build-logic/, buildSrc/ and gradle/ carry the Gradle configuration. detekt-custom-rules/ and detekt-gitlab-output-plugin/ are custom static analysis, and ProtonStyle.xml is the agreed Java code style, imported through File >> Settings >> Editor >> Code style >> Import Scheme in Android Studio. Kotlin uses ktlint with default rules instead.

There is also a CI image. The Makefile builds a Docker image for the project's CI, with targets named image, local, debug-local, deploy-local and login-deploy. The comments in that file reference CI_REGISTRY, CI_DEPLOY_USER and CI_JOB_TOKEN, and it expects a .env file. The default branch variable is development, and the latest tag is derived from MAIN_BRANCH_FOR_LATEST, also development. That is a GitLab-oriented pipeline, and it is separate from the Android build itself.

The README states the preferred tech stack for new work: Kotlin, MVVM, data-binding and coroutines. That is a real constraint on contributions, not a suggestion. Large refactors that do not conform are likely to be rejected, and the CI checks code style on every pull request before tests run. The repository also carries .semgrep.yml, .gitleaks.toml and .grype.yaml, so secret scanning and dependency scanning are part of the pipeline.

Installing ProtonVPN on Android without building anything

Most people should not build this. The README links three distribution channels: Google Play under the package name ch.protonvpn.android, F-Droid at f-droid.org/packages/ch.protonvpn.android, and the GitHub releases page. The homepage points at protonvpn.com/download-android. There is no command to run for this route; you install the app from one of those three sources and sign in.

One detail matters if you care about which binary you are running. The README states that all builds except the F-Droid one are signed with the same key, and it publishes the SHA256 fingerprint for ch.protonvpn.android. The repository includes verify_apk_signature.sh at the top level, which suggests signature checking is a supported workflow. If you download an APK from somewhere other than these three sources, the fingerprint is the thing to compare.

Building the open source variant with Gradle

The build instructions are short and assume a working Android toolchain. The README lists four prerequisites: SDK, NDK, CMake and SWIG. The NDK and SWIG requirements are consistent with native code being compiled as part of the build, though the README does not say which components are native.

After cloning, the debug build command is:

bash
./gradlew assembleProductionVanillaOpenSourceDebug

The README also says you can open the project and build it in Android Studio instead. The task name encodes two variants: Production and VanillaOpenSource. The README does not document what differs between them, so if you need to know which features the open source flavor includes, the task name is all you have to go on.

A release build needs signing keys passed as Gradle properties:

bash
./gradlew assembleProductionVanillaOpenSourceRelease -PkeyStoreFilePath=<keystore> -PkeyStoreKeyAlias=<alias> -PkeyStorePassword=<pass> -PkeyStoreKeyPassword=<key-pass>

The README does not document rollback, and it does not describe how to produce a build that matches the Play Store binary. Treat a locally signed release as your own build, not a reproduction of Proton's.

Running the checks the project runs on pull requests

The README states that internal CI checks every pull request for code style and runs the tests, and that the same checks can be run locally. It gives four commands:

bash
gradlew checkstyle
gradlew detekt
gradlew test
gradlew androidTest

Note the missing ./ on the first word. The README writes them without it, while the build instructions use ./gradlew. On a Unix shell the version without ./ will not find the wrapper unless the current directory is on your PATH, so use ./gradlew if you are on Linux or macOS. androidTest requires a connected device or emulator; the other three do not.

One more housekeeping command appears in the contributing section: after adding or updating open source dependencies, run gradlew updateLicensesJson to refresh attributions. Skipping it leaves the attribution file out of date, which is a licence hygiene problem in a GPLv3 project that bundles third-party code.

The contribution terms are unusual and worth reading first

The README asks contributors to agree to three terms: assign all copyright related to the contribution to Proton AG, certify the contribution was created in whole by the contributor, and accept that the project and the contribution are public and that a record is maintained indefinitely and may be redistributed with the project or the open source licences involved. The first term is a copyright assignment, not a licence grant. That means you give up ownership of your patch rather than licensing it to the project.

This is a real friction point for some contributors, and it sits alongside a GPLv3 licence on the distributed code. The README does not explain why the assignment is required. If you are contributing on behalf of an employer, or you want to retain rights to your work, this is the paragraph to read before you open a pull request. Nothing here is legal advice; the terms are simply what the README states.

Where the open source build is the wrong tool

Three cases stand out. First, if you want a VPN client to embed in your own product, this is not it. It is an application, and the repository exposes no documented API or SDK surface. Second, if you need to understand or reimplement the ProtonVPN service, the README describes the client build and nothing about the protocol negotiation or the backend. The ikev2, openvpn and strongswan topics name technologies, not interfaces.

Third, if reproducible builds matter to you, the README does not claim that a local build matches the published binaries. It documents a debug task and a signed release task, and it publishes the signing fingerprint for the official builds, but it does not describe build reproducibility or provide a verification path from source to store binary. That gap is the honest limit of what this repository documents.

A fourth, smaller case: the F-Droid build is signed with a different key than every other build, by the README's own statement. If you need signature continuity across update channels, you cannot switch between F-Droid and the other sources without uninstalling.

Alternatives and how they differ

The obvious alternative is WireGuard's official Android client. The difference is architectural rather than cosmetic: WireGuard implements a single protocol in the kernel and its Android app is a thin configuration and control layer, while this repository lists ikev2, openvpn and strongswan among its topics and therefore carries multiple tunneling paths plus the UI to choose between them. If you want one protocol and a small code surface, WireGuard's client is the smaller thing. If you want a consumer product with account management, server selection and multiple protocols, this repository is closer to that.

A second alternative is building your own client on top of a protocol library, for example strongSwan's Android integration, which is one of the components named in this repository's topics. That gives you control over the UI and the server list, at the cost of writing the account, profile and update machinery yourself. This repository already contains that machinery, which is exactly why it is large and why the README spends most of its length on build and contribution rules rather than on features.

Editorial conclusion

Adopt this repository if you want the official ProtonVPN Android client under GPLv3, if you need to inspect or rebuild it, or if you are contributing Kotlin in the MVVM style the README asks for. Do not adopt it if you are looking for a library to embed in your own VPN product, if you need a documented server API, or if you expect the open source build to match the Play Store build exactly. Before you start, verify that you have the Android SDK, NDK, CMake and SWIG installed, and check the signing certificate fingerprint against the one in the README, because the F-Droid build uses a different key.

Frequently asked questions

How do I download the ProtonVPN Android app?

The README points to three sources: Google Play under the package name ch.protonvpn.android, F-Droid at f-droid.org/packages/ch.protonvpn.android, and the GitHub releases page. The project homepage is protonvpn.com/download-android.

How do I install the ProtonVPN Android app on a device?

Install it from Google Play, F-Droid or the GitHub releases page listed in the README, then sign in. Building from source is a separate path that requires the Android SDK, NDK, CMake and SWIG.

How do I build the ProtonVPN Android app from source?

Install the SDK, NDK, CMake and SWIG, clone the repository, then run ./gradlew assembleProductionVanillaOpenSourceDebug. A release build additionally needs signing keys passed as -PkeyStoreFilePath, -PkeyStoreKeyAlias, -PkeyStorePassword and -PkeyStoreKeyPassword.

Is the ProtonVPN Android app free and open source?

The README states the code and datafiles are licensed under GPLv3, copyright Proton AG. Builds other than the F-Droid one are signed with the same key, and the README publishes the SHA256 fingerprint for ch.protonvpn.android.

What licence do contributions to the ProtonVPN Android app fall under?

The README asks contributors to assign all copyright related to the contribution to Proton AG, certify the contribution was created in whole by them, and accept that it is public and may be redistributed. That is a copyright assignment rather than a licence grant.

Official sources

  1. License: GPL-3.0
  2. Project website
  3. ProtonVPN/android-app on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/protonvpn-android-app.svg)](https://hysenlabs.com/projects/protonvpn-android-app)