Tenebra is an open-source VPN client for Windows designed to provide secure and flexible network connections using the sing-box core. It offers a desktop interface optimized for managing multiple protocols, including VLESS/REALITY, Hysteria2, AmneziaWG, Shadowsocks, Trojan, and VMess.
Key Features:
Multi-protocol support with a unified configuration model.
Smart routing that keeps Russian traffic direct while tunneling the rest.
Protocol fallback for seamless switching between blocked or throttled connections.
Per-app split tunneling to exclude or include specific applications.
Honest leak detection with no false positives, ensuring accurate security insights.
Desktop niceties like system tray integration, notifications, and a clean UI.
Audience & Benefit:
Ideal for privacy-conscious users who need flexibility in managing VPN connections. Tenebra is particularly beneficial for those seeking to bypass regional restrictions while maintaining low latency for local traffic.
Tenebra can be installed on Windows via winget and includes an updater for seamless updates.
Installer sets up the background service. The installer is not Authenticode-signed; SmartScreen may warn.
macOS / Linux
For advanced users: a privileged helper is required; setup varies by package. No native live-tunnel validation for 0.6.0. Installation guide.
Android / iOS
Outside the 0.6.0 release. Android is experimental; iOS is a scaffold.
Two ways to use Tenebra
Full mode puts connection controls, servers, routing and diagnostics within reach.
0.6.0 interface preview with demo data; not a live connection measurement.
Simple mode — subscription, server and connection in one flow
0.6.0 interface preview with demo data; not a live connection measurement.
Connect in three steps
Install and open Tenebra. On macOS and Linux, complete the helper setup first.
Import your subscription or server link. Paste a URL or share link, open a text file, or import a QR image. Obtain connection details from your provider or your own server.
Select a server and connect. Start with Smart routing for direct Russian/LAN destinations and a tunnel for other traffic; choose Global to route through the tunnel.
What you get
Flexible imports. VLESS/REALITY, Hysteria2, Shadowsocks, Trojan and VMess links; subscription lists, base64 and Clash/Mihomo YAML.
Routing controls. Smart, Global and Direct modes, plus per-app include/exclude lists.
Connection fallback. Tries the last working node first, then configured protocol alternatives when available.
Optional Windows DPI bypass. Integrated zapret with an embedded bundle and controlled updates. Results depend on your network. How it works.
Useful diagnostics. Public-IP observations, a best-effort DNS probe, logs and distinct service, engine and connection errors.
Desktop controls. Tray actions, profiles, live traffic graphs, light/dark themes and Russian/English interfaces.
Project status and known limits
0.6.0 is an early desktop release. Recorded Windows checks cover the nine-step installation sequence, both interfaces under an ordinary user at 100% and 150% display scaling, IPv4 tunnelling, system-proxy handling and selected crash/recovery cases. This is a limited acceptance scope; it does not establish compatibility with every subscription or network.
Windows protection: the complete IPv6, BFE and reboot acceptance matrix remains open. A saved protection setting is separate from confirmed enforcement; do not read it as a universal leak-prevention guarantee. Acceptance details.
macOS and Linux: packages are available, but native live-tunnel acceptance has not been completed. macOS is unsigned and unnotarized; Linux system-proxy mode is unsupported.
AmneziaWG: links can be imported, but the bundled stock engine does not apply AWG obfuscation parameters; it uses plain WireGuard.
Diagnostics: the IP/DNS check reports what it can observe; it does not certify all traffic paths.
For help, use Discussions. Report bugs with your version, operating system and relevant logs through the issue form. Remove subscription URLs, credentials and other private details before sharing logs. For security reports, follow SECURITY.md.