Xray clients for every device | NetGuardVPN
GuideNetGuardVPN13 min read

Xray clients for Windows, Android, iPhone, macOS, Linux, and TV

Which apps work with VLESS and Xray, how clients differ across platforms, and how to choose and import a connection profile safely.

Updated:

An Xray client is an app that imports a connection profile, runs a compatible networking core, and routes device traffic according to its rules. The client usually does not sell server access by itself: you still need a configuration from a service or your own administrator.

This guide covers popular options for desktops, phones, TVs, and routers. Inclusion does not mean that every app supports every new Xray feature. Before installing, check the protocol, transport, REALITY, XHTTP, and XTLS Vision requirements in your profile.

For a quick start with NetGuard: use the official NetGuardVPN app where available, or Happ with the guide for your platform. Import the supplied link as a whole.

What an Xray app contains

Most clients combine three parts:

  1. User interface — profile import, server selection, logs, and the connection switch.
  2. Networking core — Xray-core, libXray, or a compatible implementation that understands VLESS, VMess, Trojan, and other protocols.
  3. Operating-system integration — TUN/VPN APIs, system proxy settings, routes, and DNS.

Two clients with similar interfaces can therefore support different features or update their embedded cores on different schedules.

Quick choice by device

Platform Simple starting point Other known options NetGuard guide
Windows NetGuardVPN, Happ v2rayN, Invisible Man — Xray Open
Android NetGuardVPN, Happ v2rayNG, X-flutter, SimpleXray Open
Android TV NetGuardVPN, Happ Android clients with a TV interface Open
iPhone and iPad Happ, INCY Streisand, OneXray Open
macOS Happ v2rayN, V2RayXS, Furious Open
Linux Happ v2rayA, v2rayN, Furious Open
OpenWrt PassWall / PassWall 2 ShadowSocksR Plus+ Depends on router firmware

The public app list changes. Projects can move, disappear from stores, or temporarily lag behind the current core. Download installers only from a developer page you have verified.

Windows

NetGuardVPN

The official app provides a quick sign-in and retrieves the active subscription automatically. It is the main option when you do not need custom routing rules or several third-party configurations.

Happ

Happ is a cross-platform Xray client. It can import subscriptions and supports VLESS with REALITY, VMess, Trojan, Shadowsocks, and SOCKS. It is useful when you want a similar interface on Windows, macOS, Linux, Android, and Apple devices.

v2rayN

v2rayN is one of the best-known open-source graphical clients in the V2Ray/Xray ecosystem. Current branches support Windows, Linux, and macOS and can work with multiple cores. Because it exposes many network settings, new users should import the supplied subscription before changing DNS, TUN, or routing options.

Invisible Man — Xray and other GUIs

The Xray-core project also lists Invisible Man — Xray, Furious, OneXray, and other Windows clients. Consider them when the primary option does not suit the interface or device architecture. Check the latest release date and explicit support for your profile fields.

Step-by-step setup: NetGuardVPN on Windows.

Android and Android TV

NetGuardVPN

The official build is available for ARM64, used by most current devices, and x86_64 for some emulators. The Android TV interface is adapted for television controls, and sign-in can be confirmed from another device.

Happ

Happ is distributed through Google Play and as an official APK. It works on phones and Android TV, imports subscription links, and creates a system VPN connection.

v2rayNG

v2rayNG is an open Android client that supports Xray-core and v2fly-core. It suits users who need manual profiles, routing, and mode selection. Install an APK from the official 2dust repository; store availability can vary by region.

Other options

Xray-core also lists X-flutter, SimpleXray, OneXray, and other Android clients. The word Xray in a name does not guarantee an identical feature set. Check REALITY, XHTTP, and current VLESS-link support carefully.

Guides: Android and Android TV.

iPhone and iPad

iOS clients use Network Extension and the system VPN API. Apple limits background networking processes, so the core is commonly integrated as a library or compatible implementation rather than launched as an ordinary standalone process.

Happ

Happ has App Store variants for different regions. It supports subscription import and everyday profile switching. Confirm that you are opening the developer’s official listing before installing.

INCY

INCY is an alternative iPhone and iPad client with subscription-link import. It can be useful when Happ is unavailable in your region or you prefer a different interface.

Streisand and OneXray

Both appear in Xray’s compatible-client listings. Supported transports and functions can change between releases, so verify your exact profile before paying or importing access.

Shadowrocket, Loon, Egern, and Quantumult X

These are third-party networking tools listed by Xray-core as supporting parts of the VLESS/XTLS/REALITY ecosystem. They do not necessarily run Xray-core internally and may use their own rule formats. For a simple connection, do not choose a complex toolbox only because it has more settings.

Guide: connect NetGuard on iPhone and iPad.

macOS

Happ

Universal builds are available for Apple Silicon and Intel. Happ is convenient if you want to use the same client on a phone and a computer.

v2rayN

Current v2rayN releases include macOS builds as well as Windows and Linux versions. Check the operating-system requirements, CPU architecture, and core-installation notes for the specific release.

V2RayXS, Furious, and other options

The Xray-core list also names V2RayXS, Furious, OneXray, GoXRay, and other macOS clients. Some target advanced users and may require manual system-proxy configuration.

Guide: NetGuard on macOS.

Linux

Happ

The project publishes DEB and RPM packages for x64 and ARM64, plus packages for Arch Linux. Check the device architecture before downloading.

v2rayA

v2rayA provides a browser-based interface for proxy management on Linux and OpenWrt. It works well on a desktop, home server, or gateway when centralized control is useful. It supports several protocols, including VMess, VLESS, Shadowsocks, and Trojan.

v2rayN and Furious

Cross-platform graphical clients can be more convenient than a web panel on a regular desktop. Linux build availability and package formats depend on the release.

Plain Xray-core

Xray-core can run without a GUI using a JSON configuration and systemd. This is appropriate for a server or experienced administrator. A maintained GUI is usually safer for a regular user because it reduces mistakes in transport, routing, and DNS fields.

Guide: NetGuard on Linux.

Routers and home gateways

For OpenWrt, Xray lists PassWall, PassWall 2, ShadowSocksR Plus+, and luci-app-xray. XRAYUI and fancyss are seen on Asuswrt-Merlin. Router installation affects the entire home network, so take extra care:

  • confirm that the model and firmware version are supported;
  • back up the router configuration;
  • check available memory and CPU architecture;
  • decide which domains and devices should connect directly;
  • never expose the management panel to the public internet.

If only one laptop or phone needs the connection, a local app is usually easier to configure and troubleshoot.

What to check when choosing a client

1. Profile compatibility

Check more than VLESS. Confirm the transport (raw, xhttp, grpc, websocket), protection (tls, reality), and flow. A current profile may require a recent core.

2. Installation source

Use an official store, project website, or the Releases section in the developer’s repository. Repacked installers and third-party APK catalogs can add unwanted code.

3. Update history

Network protocols and operating-system APIs change. Review release dates, changelogs, and open issues, but do not judge a project only by its star count.

4. Operating mode

  • TUN/VPN mode sends traffic from most apps through a virtual interface.
  • System proxy changes HTTP/SOCKS settings that not every app follows.
  • Routing or split tunneling sends selected traffic directly but makes DNS and troubleshooting more complex.

5. Project transparency

Open source helps people inspect changes, but it does not prove that a distributed binary is safe. Signatures, official distribution channels, developer reputation, and prompt security updates still matter.

Import a profile safely

  1. Install the client from a trusted source.
  2. Get a fresh link from the service’s official account or bot.
  3. Copy the complete link without sending it to anyone else.
  4. Choose import from clipboard, subscription URL, or QR code in the client.
  5. Allow creation of a VPN configuration when the operating system asks.
  6. Select the imported profile and connect.
  7. After testing, remove the link from shared clipboards and unsecured notes.

If the profile will not connect

Start with simple checks:

  • does the internet work without the client?
  • is the subscription still active?
  • was the full link copied?
  • are both the app and its embedded core current?
  • is another VPN, proxy, antivirus, or Private DNS interfering?
  • is the device time correct, especially for VMess and TLS?
  • does the same profile work on another network?
  • does the log show a specific DNS, TLS, REALITY, or timeout error?

Do not publish a full log when it contains a UUID, server address, subscription URL, or other access keys. Redact secret fields before contacting support.

Which client should I use for NetGuard?

Start with the official NetGuardVPN app on Windows, Android, and Android TV. Happ is available for macOS, Linux, and Apple devices; INCY is another option on iPhone and iPad. Alternative clients are useful for advanced workflows but are not required for a normal connection.

To understand what a client imports, read What is VLESS?. If you are choosing between technologies, use the VLESS, VMess, Trojan, Shadowsocks, WireGuard, and OpenVPN comparison.

Sources and project directories