2026-07-29 22:03:28 +00:00
2026-07-30 00:48:07 +03:00
2026-07-30 00:36:33 +03:00
2026-07-29 22:03:28 +00:00

koridor

koridor

VPN over your own SSH server.

License: Proprietary Platform Status


koridor is a full-device VPN client built around a single idea: you already have a server you trust — just tunnel through it.

Instead of operating its own VPN infrastructure, koridor routes your device's traffic through a plain SSH server you configure yourself. There's no koridor-operated backend, no account, and no third party in the middle.

Why koridor?

Most VPN apps ask you to trust the app vendor's servers. koridor doesn't have any — it connects to a server you already own or personally trust, using nothing more exotic than standard SSH port forwarding on the wire. If you can run sshd, you can run a koridor server.

Features

  • Full-device tunnel — a TUN-based VPN, not just an app-aware SOCKS proxy. Every app on the device is covered, with no per-app setup.
  • Bring your own server — connects to any SSH server with AllowTcpForwarding yes. No special server-side software required.
  • Zero-friction onboarding — scan a QR code exported from your server, toggle on, done.
  • Fail-closed reconnects — transient drops are retried with exponential backoff; if the tunnel can't recover, the route is torn down rather than silently leaking traffic in the open.
  • Tunnel-only DNS — lookups are resolved through the server's own resolver over the tunnel, never leaked to a third-party DNS provider.
  • No telemetry — no analytics, crash reporting, or usage tracking of any kind.
  • Cross-platform — Linux, Windows, Android (macOS and iOS planned).

Download

Android

Get it on Google Play

Linux · Windows

Releases are published on the Releases page.

macOS · iOS

Coming soon.

Architecture

Flutter UI (Dart)
      │
FFI (cdylib)
      │
koridor engine (Rust)
      ├── TUN device
      ├── smoltcp netstack (packets → TCP flows)
      ├── russh SSH client (direct-tcpip per flow)
      └── Route manager

Each TCP flow captured off the TUN device is proxied over its own SSH direct-tcpip channel — the same kind of traffic an ordinary SSH port-forward produces, indistinguishable on the wire from routine SSH use.

The TUN device and OS route management layer is shared with Konduit, other VPN client from K-Ops Oy , and is published for transparency and audit as konduit-platform.

Security

  • Your SSH private key and passphrase are stored only in the OS secure credential store (Android Keystore / platform-equivalent) and are only ever sent to the server you configure, as part of establishing the tunnel.
  • All traffic between client and server is carried inside the SSH transport.

See the Privacy Policy for full details on what koridor does and does not process.

Support & Contributing

Bug reports and vulnerabilities: contact the maintainer directly via the address shown in the app's About screen.

Contributing: core development is handled internally. We do not currently accept external pull requests.


About

Created by Eugen Kaparulin. Official binaries distributed by K-Ops Oy.

© Eugen Kaparulin. All rights reserved. Privacy Policy

Description
No description provided
Readme 93 KiB
Languages
Markdown 100%