3.9 KiB
koridor is a full-device VPN client built around a single idea: you already have a server you trust — just tunnel through it.
Instead of operating its own VPN infrastructure, koridor routes your device's traffic through a plain SSH server you configure yourself. There's no koridor-operated backend, no account, and no third party in the middle.
Why koridor?
Most VPN apps ask you to trust the app vendor's servers. koridor doesn't have any — it connects to a server you already own or personally trust, using nothing more exotic than standard SSH port forwarding on the wire. If you can run sshd, you can run a koridor server.
Features
- Full-device tunnel — a TUN-based VPN, not just an app-aware SOCKS proxy. Every app on the device is covered, with no per-app setup.
- Bring your own server — connects to any SSH server with
AllowTcpForwarding yes. No special server-side software required. - Simple onboarding — set up a connection profile, toggle on, done.
- Fail-closed reconnects — transient drops are retried with exponential backoff; if the tunnel can't recover, the route is torn down rather than silently leaking traffic in the open.
- Tunnel-only DNS — lookups are resolved through the server's own resolver over the tunnel, never leaked to a third-party DNS provider.
- No telemetry — no analytics, crash reporting, or usage tracking of any kind.
- Cross-platform — Linux, Windows, Android (macOS and iOS planned).
Download
Android
Linux · Windows
Releases are published on the Releases page.
macOS · iOS
Coming soon.
Architecture
Flutter UI (Dart)
│
FFI (cdylib)
│
koridor engine (Rust)
├── TUN device
├── smoltcp netstack (packets → TCP flows)
├── russh SSH client (direct-tcpip per flow)
└── Route manager
Each TCP flow captured off the TUN device is proxied over its own SSH direct-tcpip channel — the same kind of traffic an ordinary SSH port-forward produces, indistinguishable on the wire from routine SSH use.
The TUN device and OS route management layer is shared with Konduit, other VPN client from K-Ops Oy , and is published for transparency and audit as konduit-platform.
Security
- Your SSH private key and passphrase are stored only in the OS secure credential store (Android Keystore / platform-equivalent) and are only ever sent to the server you configure, as part of establishing the tunnel.
- All traffic between client and server is carried inside the SSH transport.
See the Privacy Policy for full details on what koridor does and does not process.
Support & Contributing
Bug reports: file an issue on Gitea Issues.
Vulnerabilities: report directly to koridor@k-ops.eu.
Contributing: core development is handled internally. We do not currently accept external pull requests.
About
Created by Eugen Kaparulin. Official binaries distributed by K-Ops Oy.
© Eugen Kaparulin. All rights reserved. Privacy Policy
