Open-source project
ProtonVPN/win-app avatar
ProtonVPN/win-app

ProtonVPN/win-app: the official Proton VPN Windows client and what its source tree reveals

Official ProtonVPN Windows app

2,544 stars413 forksC#GPL-3.0

At a glance

What is it?
ProtonVPN/win-app is the GPL-3.0 source of the official Proton VPN client for Windows, split between a WPF GUI, a privileged service, a patched OpenVPN build and a kernel callout driver. It is worth reading if you want to audit how the tunnel is wired, not if you just want to install a VPN.
Who is it for?
Adopt this repository if you are auditing or building the Proton VPN Windows client itself, or if you need to see how a privileged VPN service, a firewall filter library and a kernel callout driver fit together in one Visual Studio solution. Do not adopt it as a general purpose VPN library or as a way to get a tunnel into another application: the GUI drives the service, the service drives OpenVPN, and none of that is packaged for reuse.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 9 days ago.
What is it written in?
Mainly C#, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the Proton VPN Windows client actually is

This repository holds the Proton VPN Windows app, the client that authenticated Proton VPN users run on Windows. The README is explicit about the audience: the app is intended for every Proton VPN service user, paid or free, and supports all functionality available to authenticated users. Signup is not part of the app; it happens on the website. So the repository is not a general purpose VPN toolkit and not a library you link against. It is the product itself, published as source under GPL-3.0.

The practical consequence is that the interesting question is not "what does this do" but "what does it drag onto the machine". The README lists five interacting parts: the GUI application, the Proton VPN Service, OpenVPN, the TAP adapter, and the Split Tunnel driver. Four of those five are privileged or kernel level. Installing the client means installing a Windows service, a network adapter driver and a kernel-mode callout driver. That is the normal shape of a commercial VPN client on Windows, and it is also why the source is worth reading rather than the marketing page.

How the GUI, the service, OpenVPN and the callout driver fit together

The division of labour is documented and fairly clean. The GUI app is installed to "C:\Program Files\Proton\VPN\<version>" with ProtonVPN.exe as the entry point, and it starts the Proton VPN Service when launched and stops it when closed. The service executable, ProtonVPNService.exe, lives in the same directory and is responsible for interaction with OpenVPN, managing the Windows firewall, and the Split Tunnel driver. During installation the service is configured to be started and stopped by unprivileged interactive users, which is how a normal user account can bring the tunnel up without an elevation prompt on every connect.

The tunnel itself is OpenVPN, installed under "Resources" in the same versioned directory. The README states that a new OpenVPN process starts on each connect and closes on disconnect, and that communication with it goes through a TCP management interface. One detail stands out: the OpenVPN config file is static and does not change per VPN server. Server selection therefore happens through the management interface rather than by rewriting config, which keeps the on-disk configuration constant and reduces the surface where a per-server file could be tampered with.

The build is not stock OpenVPN. It is built from official source with a patch to support the Proton VPN specific TAP adapter, in the separate win-openvpn repository. The TAP adapter, "TAP-ProtonVPN Windows Adapter V9", is likewise built from official source with a patch for the Proton VPN name and identification, in win-tap-adapter. If you build from this repository expecting upstream binaries to slot in, that assumption is wrong.

The kernel-mode "ProtonVPN Callout Driver" handles two jobs: redirecting socket bindings when Split Tunnel is enabled, and preventing DNS leaks by sending a SERVFAIL response packet for DNS requests made from interfaces other than the one Proton VPN uses. It is installed as a system service and is started on connect and stopped on disconnect by the service. That is a real design commitment. DNS leak prevention is enforced in the kernel rather than by hoping applications respect an adapter metric.

Building and running the client from source

The README does not carry build steps; it points at BUILD.md for detailed build information, and at COPYING.md for licensing and CONTRIBUTING.md for the contribution policy. If you only want the client, the README says to download the latest stable release from the Proton VPN website or from the official GitHub repository's releases page. Building is the path for people modifying the client, not for people who want a VPN.

The solution file at the repository root is ProtonVPN.slnx, and the projects live under src. The Setup folder holds Advanced Installer project files, and one dependency is called out explicitly: the latest successfully built TAP adapter installer file in Setup/ProtonVPNTap-SetupFiles is required to build the Proton VPN installer. That is a hard ordering constraint, not a suggestion.

For a debug build, the app optionally loads configuration from ProtonVPN.config in the app directory. The README notes this file is not deployed during install, and that if it is missing or holds invalid values the app tries to save the default configuration it uses. A minimal file for inspecting HTTP traffic looks like this, with the empty object disabling TLS certificate pinning:

json
{
  "TlsPinningConfig": {}
}

With that in place, the README says you can monitor the GUI app's HTTP traffic with Fiddler or another tool. Do this on a disposable machine and a test account. Turning off pinning on a client that talks to an authentication backend is exactly the kind of change you do not want sitting on a daily driver.

When the app runs, logs land in two places. GUI logs go to "%LOCALAPPDATA%\ProtonVPN\Logs" and service logs go to "%ALLUSERSPROFILE%\ProtonVPN\Logs". Those two directories are the first place to look when a connection fails, and the second one requires administrator rights to read.

There is also a manual service registration path. Passing "install" on the command line to ProtonVPNService.exe installs the service and "uninstall" removes it. The README warns that this method does not configure service security settings, so it is a debugging tool rather than a supported deployment route.

bash
ProtonVPNService.exe install

Where the design costs you: kernel components and no rollback story

The callout driver is the sharpest edge in this repository. It is kernel-mode code, it is installed as a system service, and it is part of the normal install path for a consumer VPN. That is a defensible choice for enforcing split tunnel routing and DNS leak prevention, and it is also a much larger blast radius than a userspace-only client. A bug in that driver is not a failed connection; it is a system-level fault. The README does not document rollback, and it does not describe a recovery path if the driver is left in a bad state after an interrupted upgrade. For a project of this scope that is a gap.

The versioned install directory, "C:\Program Files\Proton\VPN\<version>", is a sensible arrangement for side-by-side upgrades, but the README does not say how old versions are removed or whether the previous version is retained after an update. The update module and update service exist as separate projects (ProtonVPN.Update and ProtonVPN.UpdateService), which tells you updates are handled by a service rather than by the GUI, but the README stops there.

This is also the wrong tool for several common jobs. It is not a way to add VPN connectivity to your own application; there is no documented API surface for that, and the service contract is internal plumbing between the GUI and the service. It is not a cross platform client. And it is not useful to anyone who has not authenticated with Proton VPN, since the README ties supported functionality to authenticated users.

ProtonVPN/win-app compared with a plain OpenVPN install

The obvious alternative is installing OpenVPN directly and pointing it at a provider's configuration. The difference is not the tunnel; both end up running OpenVPN. The difference is everything around it. A plain OpenVPN install gives you a config file per server, a client you start yourself, and no privileged service managing firewall rules on your behalf. ProtonVPN/win-app gives you a service that owns the firewall, a static OpenVPN config with per-server selection over the management interface, a patched TAP adapter, and a kernel driver for split tunnel and DNS leak handling.

That trade is easy to state. The plain install is auditable in an afternoon and depends on upstream binaries; the Proton client is a multi-project Visual Studio solution with C# and C++ components, WPF and MVVM on the GUI side, and its own patched forks of OpenVPN and the TAP adapter. You get enforcement and a supported product experience, and you give up the ability to reason about the whole thing quickly. If your requirement is a tunnel you fully understand, the plain install wins. If your requirement is a client that keeps DNS from leaking outside the tunnel without cooperation from every application, the callout driver is doing work that a config file cannot.

Licence terms and the ongoing cost of tracking releases

The repository is GPL-3.0, with the README pointing at COPYING.md for licensing information and LICENSE at the root. If you redistribute a modified client, the GPL-3.0 obligations travel with it. Note also that the GPL covers this repository, not the Proton VPN service it connects to, and not the separate win-openvpn and win-tap-adapter forks, which have their own terms. Check each before you assume a uniform licence across the stack. This is a description of what the files say, not legal advice.

The maintenance picture is straightforward from the release history. Three releases, v5.1.6, v5.1.7 and v5.1.8, are timestamped 2026-09-22, and the last push to the default branch was on 2026-09-22. The repository is not archived. For anyone tracking it, the cost is not reading diffs; it is rebuilding the stack. A change to the TAP adapter or the callout driver means rebuilding those components and regenerating installers, and the installer build depends on a prebuilt TAP adapter installer being present in Setup/ProtonVPNTap-SetupFiles. That is the bottleneck to plan around, not the C# code.

Editorial conclusion

Adopt this repository if you are auditing or building the Proton VPN Windows client itself, or if you need to see how a privileged VPN service, a firewall filter library and a kernel callout driver fit together in one Visual Studio solution. Do not adopt it as a general purpose VPN library or as a way to get a tunnel into another application: the GUI drives the service, the service drives OpenVPN, and none of that is packaged for reuse. Before building anything, read BUILD.md, confirm you have the latest TAP adapter installer in Setup/ProtonVPNTap-SetupFiles, and check the GPL-3.0 terms against how you intend to distribute the result.

Frequently asked questions

What is the ProtonVPN/win-app?

It is the source repository for the official Proton VPN Windows application, published under GPL-3.0. The README describes it as intended for every Proton VPN service user, paid or free, and notes that user signup happens on the website rather than in the app.

Is the Proton VPN Windows app free?

The README states the app is intended for every Proton VPN service user, paid or free, and that it supports all functionality available to authenticated users. It does not describe pricing for the underlying service.

How do I get the Proton VPN Windows app without building it?

The README says to download the latest stable release from the Proton VPN official website or directly from the official GitHub repository's releases page. Building from source is only needed if you are modifying the client.

Where does the Proton VPN Windows app write its logs?

GUI app logs go to "%LOCALAPPDATA%\ProtonVPN\Logs". Service logs go to "%ALLUSERSPROFILE%\ProtonVPN\Logs", which requires administrator rights to read.

What is the ProtonVPN Callout Driver used for?

The README describes it as a kernel-mode driver that redirects socket bindings when Split Tunnel is enabled and prevents DNS leaks by sending a SERVFAIL response packet for DNS requests made from interfaces other than the one Proton VPN uses. It is installed as a system service and started and stopped by the Proton VPN Service.

Official sources

  1. License: GPL-3.0
  2. Project website
  3. ProtonVPN/win-app on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/protonvpn-win-app.svg)](https://hysenlabs.com/projects/protonvpn-win-app)