Open-source project
zn0wii/satelite-proxy avatar
zn0wii/satelite-proxy

Satelite: a Tauri desktop client that switches between sing-box, Xray and mihomo

轻量、好看的 sing-box / Xray / mihomo 桌面客户端。支持clash订阅导入, 规则分流、系统代理 / TUN,macOS 与 Windows 开箱即用。

874 stars128 forksRustApache-2.0

At a glance

What is it?
Satelite is a Rust and Tauri 2 desktop proxy client for macOS, Windows and Linux that imports Clash subscriptions and lets you pick between three proxy cores. It is a serious tool for people who already know what a subscription is, and its README is honest that it is still under development.
Who is it for?
Adopt Satelite if you already have a working subscription and want one window that can switch between sing-box, Xray and mihomo without hand-editing YAML. Skip it if you need a signed, notarized macOS build or a client you never have to audit.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 3 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem Satelite is aimed at

Most desktop proxy clients pick one core and stay there. A Clash Meta user who wants Hysteria2 or AnyTLS support ends up running a second application, or hand-writing a sing-box JSON file and keeping it in sync by hand. The README frames Satelite as an answer to that split: sing-box is the default core, Xray and mihomo are one click away in the settings page, and the README claims subscriptions, rules and DNS configuration follow the switch.

The intended audience is narrow and specific. It is someone who already has a subscription link or a sing-box JSON file, understands what a rule set is, and wants a tray application rather than a terminal. The README's own framing is that it does not want to be a longer feature list, but a smaller shell around three engines. That is a design claim worth testing against the feature list that follows it, which is long.

Three cores, one listener, and a multi-core mode

The architecture is a Tauri 2 shell: a React and TypeScript frontend built with Vite, and a Rust backend in src-tauri. The README lists three cores as bundled resources, sing-box, Xray and mihomo, each with its own geodata, plus three built-in remote rule sets in .srs format.

The interesting part is what the README calls multi-core mode. In that mode sing-box keeps the main listener, and specific nodes are delegated to Xray or mihomo as secondary processes based on protocol. This is a real mechanism rather than a marketing phrase: it means the inbound port and the routing rules stay in one process while protocol-specific outbounds live elsewhere. The README also states that unsupported protocols are filtered automatically according to the active core, so the client should not generate a configuration that cannot connect.

Core binaries are fetched automatically. The README says the three cores are downloaded and updated by the application, and that a core which exits unexpectedly is restarted. The build scripts can also fetch them ahead of time into src-tauri/resources/.

Installing Satelite and importing a first subscription

The README does not document a package manager install. It points at the release artifacts and at the build scripts in the repository, so the practical path is to download a build for your platform or compile one.

For a local build, the frontend dependencies come from pnpm and the development entry point is the Tauri CLI. The README notes that if a core or a built-in rule set is missing, the application downloads it itself.

bash
pnpm install
pnpm tauri dev

If you would rather bake the cores into the bundle before building, the repository ships per-platform fetch scripts. On macOS Apple Silicon, for example, the README lists these four:

bash
./scripts/fetch-bundled-core-darwin-arm64.sh
./scripts/fetch-bundled-xray-darwin-arm64.sh
./scripts/fetch-bundled-mihomo-darwin-arm64.sh
./scripts/fetch-bundled-rule-sets.sh

On Windows the equivalent step uses PowerShell scripts, and the packaging script has a slimming flag that keeps only sing-box:

powershell
pwsh scripts/build-windows.ps1
pwsh scripts/build-windows.ps1 -SingboxOnly

Once the window is open, the README describes importing a Clash subscription, a sing-box JSON file, or a share link, either from a file, from a URL, or through a browser deep link using clash://, sing-box:// or singbox://. After import, the settings page is where you pick the core, and the home screen has a one-click latency and exit IP test that re-runs after a node switch. If macOS refuses to open the app because it is unsigned and quarantined, the README gives the command:

bash
sudo xattr -d com.apple.quarantine /Applications/Satelite.app

Where Satelite gets in the way

The clearest limitation is stated by the project itself: Satelite is still under development, and the README asks you to back up important configuration files before upgrading. That is not boilerplate. It means an upgrade can interact with your configuration in ways the project does not promise to preserve, and you should treat your sing-box JSON as the source of truth rather than whatever the app has stored.

The macOS situation is a second constraint. The README's quarantine workaround exists because the application is unsigned, so Gatekeeper blocks it on first launch. Running that xattr command is a decision about trust, not a formality, and it is the kind of step that some managed corporate machines will not allow at all.

A third issue is scope. Three bundled cores plus geodata plus three rule sets is a large download, and the README offers a --singbox-only or -SingboxOnly build flag precisely because of that. If you only ever use one core, the multi-core feature is dead weight in your installer and in your update path. The README also does not document a rollback procedure for a core update that breaks a working setup, and it does not describe what happens to your rules when you switch cores mid-session.

How it differs from a plain sing-box or mihomo install

The obvious alternative is running sing-box or mihomo directly, or using a single-core GUI wrapper around one of them. The difference in approach is real: a single-core client owns one configuration format and one routing engine, so there is nothing to translate when you change a rule. Satelite owns three, and its job is to keep subscription, rules, DNS and Hosts consistent across whichever core is active. That is more moving parts, and the failure surface is correspondingly larger.

If your subscription is Clash-only and you never need anything sing-box does, a mihomo-focused client will give you the same result with fewer processes and no core-switching layer. Satelite's case is strongest when you actually use the multi-core mode, or when you want to move between cores without rebuilding your setup. The README's proxy chain feature, which it describes as a draggable multi-hop canvas with per-hop diagnostics, is another thing a bare core install does not give you.

Licence and the cost of keeping up

The repository is Apache-2.0, which permits commercial use and modification and includes a patent grant. That covers the Satelite code. It does not automatically say anything about the three bundled cores, which are separate projects with their own licences, and the README does not discuss their terms. If you plan to redistribute a build, check each core's licence rather than assuming Apache-2.0 covers the whole bundle.

On maintenance: the last push to the repository was on 2026-09-15, and the most recent release listed is v1.0.35 from 2026-09-14, following v1.0.34 and v1.0.33 within the preceding two days. That release cadence is fast enough that pinning a version and reading the release notes before upgrading is worth the effort, especially given the README's own warning about backing up configuration. The upgrade cost is not the download; it is re-verifying that your rules, DNS settings and core choice survived the update.

Rules, DNS and the routing surface

The routing model is where most of the day-to-day work happens. The README describes multiple rule sets, local or remote .srs files, with drag-and-drop priority ordering, built-in domestic site and domestic IP rule sets, and a fallback that can be proxy, direct or block. Policies can point at a whole group of nodes, filter by keyword, or route into a proxy chain.

The DNS section is more specific than most clients bother with. The README lists DoH, DoT and FakeIP support, DNS rule sets, system Hosts and a default resolver, plus a DNS diagnostic that walks a domain through the resolution path and flags local or domestic paths in red as a leak risk. That last feature is the kind of thing that is easy to describe and hard to get right, and the README does not explain how the leak heuristic is computed. Treat the red flag as a prompt to investigate, not a verdict.

Editorial conclusion

Adopt Satelite if you already have a working subscription and want one window that can switch between sing-box, Xray and mihomo without hand-editing YAML. Skip it if you need a signed, notarized macOS build or a client you never have to audit. Before relying on it, verify that the bundled cores match the protocols your subscription uses, and keep a copy of your sing-box JSON outside the app, because the README tells you to back up important configuration files before upgrading.

Frequently asked questions

Is using a proxy server illegal?

The repository does not address legality at all. It is an Apache-2.0 licensed client for sing-box, Xray and mihomo, and what you may lawfully do with a proxy depends on your jurisdiction and your provider's terms, neither of which the README discusses.

Is there a free Wi-Fi proxy available?

Satelite does not provide any proxy service. It is a desktop client that imports a Clash subscription, a sing-box JSON file or a share link, so you still need your own server or subscription before it can route anything.

How do I proxy my internet with Satelite?

Import a subscription or sing-box JSON through the file, URL or browser deep link import, then use the system proxy toggle or TUN mode from the settings. The README lists TUN modes as system, gvisor and mixed, with options to bypass the LAN and block QUIC.

Is a proxy server free?

The README describes Satelite as a client only, and it does not mention any bundled or free proxy service. The cores it manages, sing-box, Xray and mihomo, are separate open source projects, but they are engines, not servers.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. README
  4. Releases
  5. zn0wii/satelite-proxy on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/zn0wii-satelite-proxy.svg)](https://hysenlabs.com/projects/zn0wii-satelite-proxy)