# WG Tunnel: An Advanced Open-Source WireGuard Client for Android with AmneziaWG

> WG Tunnel is a FOSS Android app for WireGuard and AmneziaWG that adds capabilities the official WireGuard client lacks: auto-tunneling based on network state, a configurable kill switch, split tunneling, encrypted DNS, and a local proxy mode for exposing the tunnel to other apps.

**wgtunnel/android** — An advanced, open-source client for WireGuard and AmneziaWG on Android.

- Repository: https://github.com/wgtunnel/android
- Website: https://wgtunnel.com
- Stars: 3,225 · Forks: 197
- Language: Kotlin
- License: MIT
- Published: 2026-09-24 · Updated: 2026-09-24 · Language: en
- Canonical page: https://hysenlabs.com/projects/wgtunnel-android

## What WG Tunnel Does and Who It Is For

WG Tunnel is an open-source Android application that serves as an alternative to the official WireGuard Android client. The README describes it as inspired by the official app but designed to fill gaps in it, specifically by adding auto-tunneling, AmneziaWG support, Lockdown Mode (a custom kill switch), and Local Proxy Mode.

The target audience is Android users who need more control over when and how WireGuard tunnels activate, users who require AmneziaWG for censorship resistance, and developers who want to integrate tunnel control into automation workflows through Android intents. The app also fully supports Android TV, which the standard WireGuard client does not.

WG Tunnel is available through Google Play, the IzzyOnDroid F-Droid repository, the project's own F-Droid repository at fdroid.wgtunnel.com, and Obtainium. The package identifier is com.zaneschepke.wireguardautotunnel. The most recent stable release at the time of this article is 5.7.5, published on 2026-09-26.

## Auto-Tunneling and the Network-Aware Activation Model

Auto-tunneling is the feature that most clearly separates WG Tunnel from the official WireGuard client. The README describes it as automatically activating tunnels based on the device's active network details. This means the app can be configured to enable a specific tunnel when the device connects to an untrusted Wi-Fi network and disable it when on a trusted one, without manual intervention.

Supporting auto-tunneling is the Deferred Endpoint Bootstrapping feature, which the README describes as safely resolving endpoints and updating peers after the tunnel is up. This addresses a reliability and leak protection problem that can occur on startup when a DNS-based endpoint cannot be resolved before the tunnel interface is active. Resolving the endpoint after the tunnel interface exists eliminates a window where unprotected DNS traffic could leak.

Handshake Monitoring provides real-time feedback on tunnel health. The README describes it as giving instant feedback on whether the tunnel's WireGuard handshake is active. This is useful for diagnosing connectivity issues without leaving the app.

Dynamic DNS Handling extends the network-aware model further: the app automatically detects when a server's IP address changes and updates the endpoint without requiring a restart. IPv6 endpoint support works the same way: the app upgrades to IPv6 endpoints or falls back to IPv4 based on network conditions, again without a restart. Together these features make WG Tunnel suitable for scenarios where the server-side IP or DNS changes regularly.

## Building WG Tunnel from Source

The app consumes published core artifacts from Maven Central by default, which covers most development scenarios. To build a debug APK from source:

```sh
git clone https://github.com/wgtunnel/android
cd android
./gradlew assembleDebug
```

For a full build that includes the native core (JNI backend, parser, hevtunnel), clone the companion core repository next to the android directory:

```sh
git clone https://github.com/wgtunnel/android
git clone https://github.com/wgtunnel/core
cd android
```

The full build requires a local dev configuration in settings.gradle.kts to switch Gradle from Maven Central to the composite build. The README shows the required includeBuild block:

```kotlin
includeBuild("../core") {
	dependencySubstitution {
		substitute(module("com.wgtunnel.tunnel:backend"))
			.using(project(":backend"))
		substitute(module("com.wgtunnel.tunnel:backend-android-jni"))
			.using(project(":backend-android-jni"))
	}
}
```

The README notes that these Gradle changes must not be committed: restore the original Maven bundle reference before opening a pull request. The core build requires JDK 21, Android NDK, make, and a C toolchain.

## AmneziaWG Support and Censorship Resistance

AmneziaWG is a fork of the WireGuard protocol designed to resist deep packet inspection and censorship, developed by the Amnezia project. WG Tunnel supports AmneziaWG versions 2.0 through 3.1 according to the README feature list.

The practical difference between WireGuard and AmneziaWG is that WireGuard's handshake is identifiable by DPI systems, while AmneziaWG introduces obfuscation at the protocol level to make the traffic harder to fingerprint. For users in environments where WireGuard is blocked, AmneziaWG support in WG Tunnel provides an alternative path without switching to a different app.

This feature is not available in the official WireGuard Android app, making WG Tunnel the relevant client for operators who run AmneziaWG servers and need an Android client that supports the protocol. The README covers AmneziaWG versions 2.0 through 3.1 specifically; earlier or later versions of the protocol are not listed as supported. Users should verify that their server's AmneziaWG version falls within that range before relying on the app for censorship-resistant connections.

## Lockdown Mode, Local Proxy, and Split Tunneling

Lockdown Mode is WG Tunnel's in-app kill switch. The README describes it as blocking all traffic while the tunnel is down, preventing data from leaving the device outside the VPN even if the tunnel drops unexpectedly. This is implemented in the app layer rather than at the system VPN kill switch level.

Local Proxy Mode exposes a WireGuard tunnel over a local SOCKS5 or HTTP proxy. The README notes this is useful for routing specific applications like browsers or firewall apps (the README gives AdGuard as an example) through the VPN without routing all device traffic through it. This is a different capability from split tunneling: split tunneling routes specific apps through the VPN at the system level, while local proxy mode routes apps that support a proxy configuration.

Split and Encrypted DNS allows DNS resolution through the tunnel using plain DNS, DNS over TLS (DoT), or DNS over HTTPS (DoH). It also supports domain-based splitting: resolving some domains through the tunnel while others go to the system resolver.

Remote Control via Android intents allows automation apps like Tasker to control tunnels and auto-tunneling programmatically, which is useful for creating workflows where tunnel activation depends on conditions beyond network state. Quick Controls round out the usability features: a Quick Settings tile lets users toggle tunnels from the Android notification shade, and home screen shortcuts provide one-tap access without opening the full app.

## WG Tunnel vs the Official WireGuard Android App

The official WireGuard Android app is the reference client published by the WireGuard project itself. It focuses on the core WireGuard functionality: importing configurations, enabling and disabling tunnels, and displaying connection statistics. It does not include auto-tunneling, AmneziaWG support, Lockdown Mode, Local Proxy Mode, or intent-based remote control.

WG Tunnel adds all of those features at the cost of greater complexity. The official app is the simpler choice for users who need basic WireGuard connectivity. WG Tunnel is the better fit for users who need automatic tunnel switching, censorship-resistant protocol support, or tight integration with Android automation tooling.

Both apps are open source. The official WireGuard Android app is licensed under the GPL. WG Tunnel is MIT-licensed, which is more permissive for downstream use. The last push to the WG Tunnel repository was on 2026-09-27, and the project publishes both stable releases (5.7.5 on 2026-09-26) and nightly builds from a separate release track. The repository includes a SECURITY.md file for reporting vulnerabilities. Translation is handled through Crowdin at translate.android.wgtunnel.com, and the README links to an invitation for community contributors. The Telegram channel and Matrix space listed in the README serve as community support channels for users who need help with configuration or encounter bugs.

## Conclusion

WG Tunnel is the right choice for Android users who need WireGuard features beyond what the official app provides: auto-switching tunnels based on Wi-Fi network, AmneziaWG for censorship resistance, a configurable kill switch, or a local proxy for routing specific browser traffic through the VPN. Users who only need a basic WireGuard client will find the official app simpler. Before deploying in a high-security context, review the SECURITY.md file in the repository and confirm that the Lockdown Mode behavior matches your leak prevention requirements, as the README describes it as an in-app kill switch rather than a system-level one.

## FAQ

### What is AmneziaWG and why does WG Tunnel support it?

AmneziaWG is a variant of the WireGuard protocol that adds obfuscation to resist deep packet inspection and censorship. WG Tunnel supports AmneziaWG versions 2.0 through 3.1, allowing users in environments where standard WireGuard is blocked to use the same app with an AmneziaWG server.

### How does WG Tunnel's Lockdown Mode differ from Android's built-in VPN kill switch?

The README describes Lockdown Mode as an advanced in-app kill switch that blocks all traffic while the tunnel is down. It is implemented at the app level rather than at the Android system VPN kill switch level, providing an additional layer of leak prevention.

### Where can I install WG Tunnel without using Google Play?

WG Tunnel is available from the IzzyOnDroid F-Droid repository, from the project's own F-Droid repository at fdroid.wgtunnel.com, and through Obtainium. The package identifier is com.zaneschepke.wireguardautotunnel.

## Sources

- [License: MIT](https://github.com/wgtunnel/android/blob/master/LICENSE)
- [Project website](https://wgtunnel.com)
- [README](https://github.com/wgtunnel/android/blob/master/README.md)
- [Releases](https://github.com/wgtunnel/android/releases)
- [wgtunnel/android on GitHub](https://github.com/wgtunnel/android)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/wgtunnel-android
