One relay. Two carriers. Independent directions.
A cross-platform relay that composes TLS/TCP and QUIC/UDP
independently for every flow.
Quick start · Ecosystem · Architecture · Live operations · Documentation · Wire protocol
Nowhere joins TLS/TCP and QUIC/UDP behind one service edge. Vector accepts local SOCKS5 traffic; Portal authenticates carriers and reaches the target. Each flow selects its uplink and downlink independently.
| Core property | What it means |
|---|---|
| Unified edge | TLS/TCP and QUIC/UDP share one service identity and lifecycle |
| Split routing | Uplink and downlink choose their carrier independently |
| Optional Morph | A keyed transform masks the TLS/QUIC wire image |
| TCP and UDP | SOCKS5 CONNECT and UDP ASSOCIATE are both supported |
| Native chaining | Portal forwards directly to Portal with no local proxy loop |
| Built-in telemetry | The same binary discovers and inspects live instances |
Use a stable Rust toolchain on a supported target, or download a prebuilt binary.
cargo build --release --lockedListen on TLS/TCP and QUIC/UDP at all interfaces on port 2000:
./target/release/nowhere "portal://change-me@*:2000"Connect to Portal and expose SOCKS5 on 127.0.0.1:1080:
./target/release/nowhere \
"vector://change-me@portal.example:2000?up=tcp&down=tcp&socks=127.0.0.1:1080"Open the local TUI from another terminal:
./target/release/nowhere tui|
CLIENT Anywhere Native Swift client with independent TCP/UDP carriers, TLS multiplexing, and Morph. App Store |
DEPLOY nowhere-sh Interactive Linux VPS deployment script for installation, upgrades, links, QR codes. Quick start |
|
CONTROL OpenCtrl Supervises Nowhere processes and exposes their telemetry through REST and SSE. API reference |
OPERATE NowhereDash Web dashboard managed through OpenCtrl, with live telemetry and protected subscriptions. Quick start |
Application
TCP / UDP
|
SOCKS5
|
v
+------------+ Uplink carrier +--------------+ Native `next` uplink +-------------+
| Vector |==================>| Entry Portal |========================>| Next Portal |
| |<==================| |<========================| (optional) |
+------------+ Downlink carrier +--------------+ Native `next` downlink +-------------+
| |
direct or SOCKS5 direct or SOCKS5
| |
v v
+------------+ +------------+
| Target | | Target |
+------------+ +------------+
Each service URL uses either a compact endpoint for both carriers on one port, or an explicit endpoint that assigns carriers, ports, and address families.
| Endpoint | Meaning |
|---|---|
@*:2000 |
TLS/TCP and QUIC/UDP on wildcard addresses, port 2000 |
@*/tcp:2006 |
TLS/TCP only, IPv4 and IPv6 |
@*/udp:2017 |
QUIC/UDP only, IPv4 and IPv6 |
@*/tcp4:2006/udp6:2017 |
TLS/TCP on IPv4 and QUIC/UDP on IPv6 |
up and down accept tcp, udp, or mix. With both carriers available,
the default is TCP; mux=1 enables TLS multiplexing.
up ↓ / down → |
tcp |
udp |
mix |
|---|---|---|---|
tcp |
TT | TQ | TT ↔ TQ |
udp |
QT | QT ↔ QQ | |
mix |
TT ↔ QT | TQ ↔ QQ | TT ↔ QQ |
T means TLS/TCP and Q means QUIC/UDP, with the uplink listed first. mix
randomly selects either carrier with equal probability for each flow and may
try the alternate route once before commitment. Portal next= applies the same
policy independently on each hop.
Carrier bootstrap Logical flow
+----------------+ +----------------+----------+-------------+
| AuthFrame | | FlowHeader | Target? | Payload ... |
| 32 bytes | | 5 bytes | variable | after READY |
+----------------+ +----------------+----------+-------------+
| |
+-- TLS: dedicated lane or Mux +-- TCP: reliable byte stream
+-- QUIC: first stream only +-- UDP: UoT or QUIC DATAGRAM
morph=1 masks the bare TLS/QUIC wire image with a transform derived from the
shared key:
TCP client -> server [ prelude 64B ][ nonce 12B ][ ChaCha20-XOR(TLS stream) ]
server -> client [ ChaCha20-XOR(TLS stream) ]
UDP each datagram [ nonce 12B ][ ChaCha20-XOR(QUIC datagram) ]
A Portal can open the next Nowhere hop directly:
nowhere \
"portal://relay-key@:2000?next=origin-key@origin.example:2000&up=udp&down=udp"next is lazy, mutually exclusive with outbound socks, and bounded to seven
hops.
The read-only TUI discovers local Portal and Vector instances. It presents traffic, carrier, process, and anonymized event data without controlling their lifecycle. Third-party clients use the same telemetry contract.
The local examples disable certificate verification by omitting sni. Public
deployments should use a trusted certificate and verified server name:
nowhere "portal://change-me@:2000?tls=2&crt=/etc/nowhere/cert.pem&key=/etc/nowhere/key.pem"
nowhere "vector://change-me@portal.example:2000?sni=portal.example&socks=127.0.0.1:1080"| Guide | Covers |
|---|---|
| Quick start | Build, run, and connect |
| Ecosystem | Clients, deployment and control tools, and share links |
| Configuration | Service URLs, options, chaining, and environment variables |
| Wire protocol | Authentication, flows, Mux, and Morph |
| Security | Certificate verification and trust boundaries |
| Operations | Deployment and runtime behavior |
| Platforms | Supported targets and platform differences |
| Telemetry | Local discovery and monitoring integrations |
See the documentation index for the complete reference.
Run the standard checks on a supported host:
cargo fmt --all -- --check
cargo test --all-targets --locked
cargo clippy --all-targets --locked -- -D warnings
cargo build --release --lockedOn macOS, Apple Container provides the reusable Linux check environment:
./scripts/check-linux.shCI covers Linux, macOS, and Windows. Release packaging covers Linux GNU/musl on x86-64 and AArch64, macOS on Apple Silicon, and Windows x86-64 MSVC. Protocol changes must update the wire document and protocol vectors together.
Nowhere is licensed under the GNU General Public License v3.0.
© 2026 NodePassProject. All rights reserved.

