VPN Protocols Explained: Which One to Use in 2026
VPN protocols explained, in plain terms
A VPN protocol is the part that decides whether you connect at all. On an open network almost anything works and the only difference is speed. On a filtered network the question is narrower: does this traffic survive deep packet inspection, or does the connection die during the handshake? This guide covers every protocol VitaminVPN sells — our own VitaminVPN app, Xray with VLESS, VMess and REALITY, WireGuard in its AmneziaWG form, OpenVPN, SSH tunnels and the MTProto proxy — what each is for, how it reaches you, and which to try first on the network you are actually sitting on.
Which appear in your panel depends on your plan: every family is a separate entitlement, so a tab you cannot see is one you have not bought. Plan contents are on the premium plans page.
First, how you receive it
Delivery matters more day to day than cryptography, because it decides how much work a new device costs you. There are five styles here: our own app with nothing to import (VitaminVPN); a subscription link carrying every server and refreshed by the app itself (Xray); a config file per server (WireGuard, OpenVPN); a credential card of host, port, username and password (SSH); and a tap-to-open link (MTProto).
VitaminVPN: our own app, and the one to try first
VitaminVPN is our own dedicated application, and it is the most restriction-resistant option we sell. There is nothing to import and no file to manage: you sign in with your VPN username and password, press connect, and the app does the rest. It finds a working path to a server for you and keeps that path working as the network around you changes — so when other tools stop connecting, this is the one built to keep going. Where filtering is aggressive, it is the first thing to try.
It runs on Android, Windows, iPhone, iPad and macOS, so a household on mixed devices installs one app everywhere. You download it from your account page and it needs nothing else. Because it is our own app rather than an off-the-shelf client, we maintain it directly against what networks are blocking right now — which is exactly why it is the recommendation, not a fallback.
Xray: VLESS, VMess and REALITY
Xray is what most people mean by "V2Ray config" or "VLESS key", and it is the strongest alternative to our own app. We run VLESS and VMess inbounds over TCP, WebSocket and XHTTP, plus Shadowsocks, and deliver all of them through one self-refreshing subscription URL. Per-server URIs exist too.
The part that matters under aggressive filtering is REALITY. A REALITY connection is a genuine TLS 1.3 session to a large, ordinary website, so to anything watching the wire it looks like normal web browsing rather than a VPN.
Be precise about the rest of the family: the plain VLESS and VMess inbounds are fast and fine on a network that is not fighting you, but they are not camouflaged and they are easy to identify. If your network is hostile, pick a REALITY entry, not the first one in the list.
Xray has broad app support with per-app import links — v2rayNG, Hiddify, sing-box, Karing, V2Box, Streisand, NekoBox, Clash Verge Rev, FlClash, v2rayN, NekoRay, OpenWrt with PassWall, and the paid Shadowrocket and Loon on iOS. Encoding differs between them, which is why we generate the link per app instead of asking you to copy and paste.
WireGuard, in its AmneziaWG form
WireGuard is the speed answer: small, instant to reconnect, and the cheapest thing here on battery. What we run is not stock WireGuard but AmneziaWG, which randomises the handshake so it does not look like a WireGuard handshake. Obfuscation is enabled in production.
That has a practical consequence. The file we generate carries obfuscation parameters the official WireGuard app will refuse. Use an AmneziaWG-compatible client. The file is generated per server when you fetch it and is tied to your account, so treat it as a secret. A MikroTik RouterOS block ships alongside it, and the MTU is set to 1280 deliberately — the larger default silently drops packets on mobile paths.
OpenVPN
OpenVPN is the compatibility answer. Almost every router, firewall and legacy client speaks it: OpenVPN Connect, Tunnelblick on macOS, OpenWrt, pfSense. The profile carries no per-user material — you type your own username and password — so the same .ovpn works for everyone on a given server.
It has no obfuscation of any kind; the OpenVPN handshake is among the most reliably fingerprinted signatures on the internet. Buy it for routers and old hardware, not for a national firewall.
SSH tunnels
An SSH tunnel arrives as a credential card — host, port, user, password — plus a ready-to-paste ssh -D command that gives you a local SOCKS proxy. Clients: OpenSSH (already on your machine, which makes it the fastest setup here), PuTTY, Termius, JuiceSSH.
It proxies the applications you point at it rather than the whole device. It works where SSH is ordinary traffic: offices, universities, hosting networks.
MTProto proxy
MTProto is for Telegram and nothing else — our own proxy with FakeTLS camouflage, delivered as a tg:// link you tap, with a shareable t.me twin. The link is derived from your password and works against every node we run, so it survives fleet changes, and changing your password invalidates every old one.
It is not a VPN. No other application's traffic goes through it, and there is no router client.
Comparison table
| Protocol | How you get it | Best for | Under aggressive filtering | You need |
|---|---|---|---|---|
| VitaminVPN | Our own app | Everyday use, and networks that block everything | The strongest option we offer; connects on its own | Android, Windows, iPhone, iPad or macOS |
| Xray / REALITY | Subscription link | A strong alternative on a filtered network | Looks like ordinary web traffic | One of 14 apps, one-tap import |
| Xray / plain VLESS, VMess | Subscription link | Speed on a permissive network | Not camouflaged | Same apps |
| WireGuard (AmneziaWG) | .conf per server |
Speed, battery, routers | Obfuscated handshake, not stealth-first | AmneziaWG-capable client |
| OpenVPN | .ovpn per server |
Routers, firewalls, old devices | No obfuscation | OpenVPN Connect, Tunnelblick, OpenWrt |
| SSH | Credential card | App-level proxy where SSH is normal | Best where SSH is ordinary | OpenSSH, PuTTY, Termius, JuiceSSH |
| MTProto | tg:// link |
Telegram only | FakeTLS camouflage | Telegram |
Which one should you try first?
Work down this list and stop at the first that connects.
- Anywhere, and especially under aggressive filtering — national DPI, handshakes dying mid-connect: start with VitaminVPN. It is built for exactly this and finds its own way through, so it is the first thing to install on any device.
- A standard-client alternative — if you would rather use an off-the-shelf app: a REALITY entry from your Xray subscription.
- Open network, you want speed — streaming, calls, large downloads: WireGuard, which beats everything else here on throughput and battery.
- A router or firewall: OpenVPN, or WireGuard if the device supports AmneziaWG.
- A corporate or campus network where outbound SSH is ordinary: the SSH card is the least conspicuous option.
- Telegram only: the MTProto link. It costs nothing to add and does not disturb other traffic.
Try two before you decide. In filtered countries networks differ street by street, and the protocol that wins on a mobile carrier often loses on home fibre.
What we do and do not claim
No protocol here is unblockable and none works everywhere all the time — anyone selling you that sentence is selling you the sentence. There is no obfuscation in OpenVPN or SSH, and MTProto is not a VPN. On privacy the statement is simple and it is the important one: we do not log or keep anything. We hold no record of what you do, our DNS resolver keeps no queries, and your traffic is carried without being inspected or stored.
Plans are on the VPN plans page, servers on the VPS page, and your configs appear immediately at Start free. Unsure what your network needs? Open a ticket with your country and carrier and we will tell you exactly what to try.