VpnHood: a C# VPN built to survive deep packet inspection
Undetectable, Fast, Cross-Platform, Free VPN
At a glance
- What is it?
- VpnHood is an open source, LGPL-licensed VPN client and server written entirely in C#. It targets networks that block ordinary VPN traffic, and it ships as desktop and mobile apps plus modular NuGet packages for people who want to run their own server.
- Who is it for?
- Adopt VpnHood if you want a self-hosted VPN whose server needs no admin privilege or network configuration, or if you are a .NET developer who wants to embed tunneling through the NuGet packages. Do not adopt it if you need a provider that hands you a ready server key, since the project is the software, not the service.
- Can I use it commercially?
- Yes, with conditions. LGPL-2.1 is a weak copyleft licence: you can use it inside commercial and closed-source software, but if you distribute changes to its own files, you must publish those changes under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 3 days ago.
- What is it written in?
- Mainly C#, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What VpnHood actually is, and who it is for
VpnHood is not a VPN subscription. It is the software that makes one work, and the README is explicit that it was "created entirely from scratch in C#". That single fact shapes everything else. The repository holds a client, a server, and a set of modular NuGet packages, all in .NET, and the client ships as a Windows MSI, a Linux package, an Android app on Google Play and an iOS app on the App Store.
The intended audience splits in two. The first group is ordinary users who need to get past a network that blocks conventional VPN protocols, which the README frames as bypassing "Advanced Firewalls" and circumventing deep packet inspection. The second group is developers and operators: people who want to run their own server, or embed VpnHood's tunneling in their own application. The developer feature list mentions an ads interface with AdMob, InMobi and Chartboost integrated, a billing interface, a REST API for user management, and MAUI support. That is a toolkit for someone building a commercial VPN product, not just a client for someone who wants a tunnel.
If you are looking for a free server key, you are in the wrong place. The project publishes software. Whoever runs the server decides who gets access.
How the tunneling and the smart proxy layer fit together
The README lists the protocols as UDP, TCP, QUIC, Cloaked and Combination. Cloaked is the interesting one, because it is the mechanism behind the undetectability claim: rather than presenting a recognisable VPN handshake, the traffic is shaped to avoid the signatures that deep packet inspection looks for. The Combination option lets a deployment mix protocols instead of committing to one.
On top of the tunnel sits a proxy layer the README calls Smart Proxies: SOCKS4, SOCKS5, HTTP and HTTPS relays, "tested in parallel, rated, rotated and auto-updated from a list URL". That is a concrete data flow. The client fetches a list of relays from a URL, probes them concurrently, assigns a rating, and rotates between them. The rating step matters more than it first appears: a list URL is a moving target, and without an active probe the client would keep selecting relays that have already gone dark.
The server side makes a claim worth pausing on: "Zero network configuration required" and "No admin privilege required". A VPN server that binds without administrative rights is unusual, and it is the design decision that makes the server deployable on a plain user account. The README also lists hot restart with sessions persisting, built-in user management, a NetScan Protector, and support for reserved proxies. Windows 10/11/Server and Linux are the supported server platforms.
Installing the VpnHood client on Windows and Linux
For most readers the fastest path is the packaged client. The README links a Windows installer directly from the latest release, and points Linux users at a dedicated wiki page for installation. Downloading the MSI and running it is the whole procedure on Windows; the README does not describe a command-line installer for that platform.
For Linux, the project's own instructions live on the wiki rather than in the repository, so treat the wiki as the source of truth for the current package format. If you are building from source instead, the repository is a .NET solution and the README advertises a "Simple Visual Studio build experience". The solution file at the top level is VpnHood.slnx, and a global.json pins the SDK, so check that file before assuming your installed .NET version will work.
Once the client is running, the README describes the first interaction as "One-click connect". That is the point where you need a server, and this is where new users most often get stuck: the client is useless without an endpoint, and the README does not include a public one.
Getting a server key is the step the README leaves to you
The client cannot connect to nothing. Someone has to run a VpnHood server and issue access, and the README does not provide a hosted endpoint or a default key. The server feature list describes built-in user management and an extendable REST API for it, which means the operator decides how keys are minted and distributed. Documentation for that flow sits on the wiki, not in the repository README.
This is the honest boundary of the project. VpnHood gives you the machinery to run a private tunnel or to operate a service for other people. It does not give you a tunnel. Any guide that promises a working VpnHood connection out of the box is describing someone else's server, not this repository.
If you are evaluating VpnHood because you want a free VPN rather than because you want to run one, the correct next step is to look at who is operating a public server, not at the source tree.
Where VpnHood is the wrong choice
The first limitation is the one above: no server, no tunnel. A user who installs the client and expects a working connection will be disappointed unless they already have access to a server.
The second is the release cadence. The most recent release is v8.1.850-prerelease, published on 2026-09-02, and the one before it, v8.1.841, is a stable release from 2026-08-04. A prerelease sitting at the top of the release list means the newest code is not the code you should be running in production. Pick the stable tag deliberately.
The third is platform scope. The client covers Windows 10/11 x64, Android phone and TV, iOS, and Linux. The server covers Windows 10/11/Server and Linux only. There is no macOS client in the README's platform list and no macOS server, so Mac users are outside the supported set. The Windows client is x64 only, which rules out ARM Windows machines.
Finally, the .NET dependency is real. The project is "fully in .NET", and the developer features assume Visual Studio, MAUI and NuGet. If your team has no .NET experience, you are adopting an ecosystem along with a VPN.
How VpnHood differs from WireGuard-based self-hosting
The natural comparison is a WireGuard deployment, and the difference is in what each assumes about the network in front of it. WireGuard is a fixed protocol with a recognisable handshake on a fixed UDP port. That makes it fast and simple, and it also makes it straightforward to fingerprint: a firewall that blocks WireGuard's port and packet shape stops it, and the usual answer is to tunnel it inside something else.
VpnHood attacks that problem at the protocol layer instead. The Cloaked protocol and the Combination option exist precisely to avoid a single identifiable signature, and the Smart Proxy layer adds a second path out through SOCKS or HTTP relays when the direct tunnel is unusable. The trade is complexity. A WireGuard config is a few lines of key material; a VpnHood deployment involves a server, a user management layer and a relay list.
In the other direction, the comparison against commercial VPN clients is about control rather than protocol. Those give you an app and an account. VpnHood gives you the app and the server, and leaves the account system to you. If you want someone else to handle keys and billing, a commercial provider is the shorter path. If you want the endpoint to be yours, VpnHood is built for that.
Licence, build cost and what to check before you commit
VpnHood is licensed under LGPL-2.1. That is a copyleft licence with a linking exception, and it is a different proposition from MIT or Apache-2.0. If you modify the library itself, the LGPL's terms attach to your modified version. If you merely link against it, the exception is designed to let you keep your own code under other terms. The repository also carries a PRIVACY.md and a separate CHANGELOG.Server.md alongside CHANGELOG.md, which tells you the client and server are versioned and documented on separate tracks. Read both before upgrading; a server changelog that diverges from the client one is a sign that a client upgrade may not be safe against an older server. None of this is legal advice, and if you plan to ship VpnHood inside a commercial product you should have the licence terms reviewed rather than reading them off a badge.
The maintenance picture is straightforward. The repository is not archived, and the last push was on 2026-09-27, one day before this article. The release line is active, with three releases between 2026-08-02 and 2026-09-02. The project also underwent a security audit by the Open Tech Fund, and the README links the published report. That report is the single most useful document to read before trusting the undetectability claim, because it is an outside assessment rather than a project statement.
Editorial conclusion
Adopt VpnHood if you want a self-hosted VPN whose server needs no admin privilege or network configuration, or if you are a .NET developer who wants to embed tunneling through the NuGet packages. Do not adopt it if you need a provider that hands you a ready server key, since the project is the software, not the service. Before committing, verify the licence terms against your distribution model, read the Open Tech Fund audit report, and check the CHANGELOG.md for the release line you intend to run.
Frequently asked questions
Is VpnHood free?
The software is free and open source under LGPL-2.1, and the client is distributed through Google Play, the App Store, a Windows MSI and Linux packages. What the project does not provide is a server or a server key, so any cost comes from whoever operates the endpoint you connect to.
Is VpnHood safe?
The README states that VpnHood underwent a comprehensive security audit by the Open Tech Fund and links the published report, which is the outside assessment to read first. The repository is not archived and the last push was on 2026-09-27.
How do I get a server key for VpnHood?
The README does not supply a public server key. The server has built-in user management with an extendable REST API, so keys are issued by whoever runs the server, and the client needs an endpoint before it can connect.
How do I use VpnHood?
Install the client for your platform, then connect to a server you have access to. The README describes the client interaction as one-click connect, and lists UDP, TCP, QUIC, Cloaked and Combination as the available protocols.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/vpnhood-vpnhood)