Protocole

VLESS-Reality

The protocol RunVPN uses by default — VLESS with the Reality transport and XTLS-Vision flow.

VLESS-Reality is the default protocol in RunVPN. It runs on the Xray engine and combines three pieces: the lean VLESS transport, the REALITY extension that makes the TLS handshake look like a connection to a well-known website, and the XTLS-Vision flow that removes redundant encryption work. The result is a connection with no observable TLS anomalies — fast, private, and stable even on networks that inspect traffic aggressively.

TLS 1.3 handshake — fingerprint of a real website You phone · laptop RunVPN server VLESS-Reality Internet 👁 The network sees: an ordinary HTTPS session XTLS-Vision splice — no re-encryption

How VLESS-Reality works

1

A lean transport on TLS 1.3

VLESS grew out of the Xray ecosystem as the successor to VMess. VMess encrypted every byte twice — once with its own crypto layer and once with TLS — and the custom crypto added CPU overhead under load. VLESS drops the redundant layer and delegates all encryption to TLS 1.3, the same cryptographic foundation every major website and banking app relies on. The protocol became leaner and faster: lower latency on burst traffic, higher throughput on sustained streams, less CPU and battery drain.

2

REALITY borrows a real TLS fingerprint

A classic TLS proxy has a weak spot — its certificate. A self-signed or private-CA certificate is an anomaly that traffic-analysis systems flag immediately. REALITY removes the anomaly: during the handshake the server presents a genuine certificate of a real, well-known website (for example a major CDN domain), and the uTLS library replicates the fingerprint of a legitimate browser. Nothing is forged or cracked — the mechanism operates at the TLS-extension level, and certificate verification passes in the standard way. To any observer the connection is an ordinary HTTPS session.

3

XTLS-Vision: no double encryption

Most of your traffic is already TLS — virtually every modern site is HTTPS. Re-encrypting that ciphertext for the tunnel wastes CPU cycles on both ends and adds latency. XTLS-Vision detects an inner TLS session inside the tunnel payload and splices it through without a second encryption pass. The inner session stays end-to-end encrypted between you and the destination site — the VPN node only ever sees ciphertext.

4

Zero configuration in the app

RunVPN configures and tunes VLESS-Reality entirely on the server side. After you sign in, the app negotiates the protocol, pins certificates and reconnects automatically when the network changes. There is no config file to import, no QR code to scan, and no connection string to paste.

VLESS-Reality vs a regular TLS proxy

VLESS-Reality
Regular TLS proxy
TLS certificate
Genuine certificate of a real website
Self-signed or private CA
Handshake fingerprint
Indistinguishable from a browser (uTLS)
Recognizable anomaly
Encryption passes
Single — inner TLS is spliced through
Double — payload re-encrypted
CPU and battery cost
Low
Higher under load
On networks with traffic inspection
Looks like ordinary HTTPS — stays stable
Flagged as an anomaly — may degrade

When to choose VLESS-Reality

One tap, the right protocol

RunVPN ships both VLESS-Reality and AmneziaWG and picks the best option for your network automatically. Download the app and connect in seconds.

DISPONIBLE SURGoogle Play App StoreiOS Bientôt
FAQ

Questions fréquentes

Is VLESS-Reality safe to use?+

Yes. It is built on TLS 1.3 — the same cryptographic foundation used by every major website and banking application. The REALITY extension does not weaken the encryption; it only changes how the handshake fingerprint appears to outside observers.

How does VLESS-Reality compare to AmneziaWG?+

Both are strong choices. AmneziaWG is UDP-based and performs best where UDP is reliable. VLESS-Reality runs over TCP/HTTPS and holds up better on networks that throttle or filter UDP. RunVPN deploys both; the app selects the best available option automatically.

Do I need any technical knowledge to use it?+

No. RunVPN configures everything automatically after sign-in. You tap connect and the app does the rest — protocol selection, server negotiation, and reconnection if the connection drops.

Will VLESS-Reality be available on iOS?+

RunVPN's iOS app is coming soon. VLESS-Reality support will be included when it launches.

À lire aussi