Repository navigation
Home
English · 简体中文
Usque is an unofficial Cloudflare WARP client for Windows, Android and Android TV. Its Rust MASQUE engine provides a system VPN, SOCKS5 and HTTP proxy through a native Flutter interface. This Wiki helps you install Usque, make your first connection and choose an optional chain exit.
This guide describes v0.2.8. Download packages from GitHub Releases, and check the release notes for your installed version. The product instructions linked below use the v0.2.8 tag; development documentation may describe newer behavior.
| Your device | Minimum system | Package to choose |
|---|---|---|
| Windows | Windows 10 22H2, build 19045 | x64-v2 or ARM64 installer EXE |
| Android / Android TV | Android 8.0, API 26 | arm64-v8a, x86_64 or armeabi-v7a APK; universal APK if you do not know the ABI |
- Download a matching official package and follow Installation and removal. Check its SHA-256 and signer against the release information before installing.
- Open Usque, complete the first-run permissions and terms steps, and register a Consumer WARP account. A WARP License Key is optional. New WARP Secret imports are not supported.
- Under VPN and local proxies, choose how your applications should connect. VPN, SOCKS5 and HTTP are enabled by default; Windows system proxy is off.
- Connect from Home. Android requests VPN consent the first time VPN is enabled; using only SOCKS5/HTTP does not require VPN consent.
| Connection option | What to do |
|---|---|
| VPN | Route system traffic through Usque, subject to direct rules and Android per-app settings. |
| SOCKS5 | Point a compatible app at 127.0.0.1:1080 by default; use remote DNS. |
| HTTP proxy | Point a compatible app at 127.0.0.1:8080 by default; HTTPS uses CONNECT. |
| Windows system proxy | Enable HTTP output first, then enable the Windows system proxy option for applications that honor it. |
These outputs share one connection. A proxy-only setup covers applications that use that proxy and does not provide a system-wide VPN Kill Switch.
Tutorial: Proton VPN with WireGuard over MASQUE
Use WARP as the transport to a Proton VPN WireGuard server, with Proton VPN as the final exit. The tutorial covers downloading your configuration, importing it under Proxy → Chain proxy → WireGuard, applying it, checking the exit and troubleshooting. Usque manages both legs of the connection.
Application → WARP / MASQUE → Proton VPN / WireGuard → Internet
| Task | Guide |
|---|---|
| Install, verify, update, uninstall or recover | Installation and removal |
| Select an OpenVPN, WireGuard, WARP via WireGuard or VPN Gate exit | Chain proxy |
| Generate or import a WARP WireGuard exit configuration | WARP via WireGuard |
| Choose DNS for country-based direct rules | Direct DNS |
| Diagnose a connection and read the results | Network Doctor |
| Resolve installation, service or permission problems | Troubleshooting |
| Understand experimental L4 mode and its limits | L4 proxy |
| Find technical references and development instructions | Documentation index |
Explicit direct rules continue to apply when a chain exit is enabled. Country-based direct rules use system DNS by default; the Direct DNS guide explains the available encrypted alternatives. On Android, blocking traffic after the VPN process ends requires system Always-on VPN and Block connections without VPN; see Android setup.
- For an ordinary bug, search existing Issues before opening a report. Include the version, platform, output mode and sanitized error message. Never attach a real VPN configuration or raw diagnostic bundle.
- For a suspected credential exposure, traffic leak or other vulnerability, use the private reporting process in the security policy.
- For code or documentation changes, read Contributing.
Usque is an independent project and is not affiliated with or endorsed by Cloudflare or Proton. A successful connection check is not proof of leak protection or improved performance. macOS is not built or released; iOS is outside this release's scope.
English
简体中文
Project / 项目