Skip to content
NodePassProjectPublic

About

A cross-platform relay that composes TLS/TCP and QUIC/UDP independently for every flow.

Topics

Resources

Security policy

Stars

456 stars

Watchers

27 watching

Forks

Latest commit

 

History

294 Commits

Folders and files

Repository files navigation

Nowhere

One relay. Two carriers. Independent directions.

A cross-platform relay that composes TLS/TCP and QUIC/UDP
independently for every flow.

Quick start · Ecosystem · Architecture · Live operations · Documentation · Wire protocol

Nowhere joins TLS/TCP and QUIC/UDP behind one service edge. Vector accepts local SOCKS5 traffic; Portal authenticates carriers and reaches the target. Each flow selects its uplink and downlink independently.

Core property What it means
Unified edge TLS/TCP and QUIC/UDP share one service identity and lifecycle
Split routing Uplink and downlink choose their carrier independently
Optional Morph A keyed transform masks the TLS/QUIC wire image
TCP and UDP SOCKS5 CONNECT and UDP ASSOCIATE are both supported
Native chaining Portal forwards directly to Portal with no local proxy loop
Built-in telemetry The same binary discovers and inspects live instances

Quick start

Use a stable Rust toolchain on a supported target, or download a prebuilt binary.

1. Build

cargo build --release --locked

2. Generate a key

Generate a shared key for <generated-key> in both Portal and Vector URLs:

./target/release/nowhere generate-key

3. Start Portal

Listen on TLS/TCP and QUIC/UDP at all interfaces on port 2000:

./target/release/nowhere "portal://<generated-key>@*:2000"

4. Get the certificate fingerprint

Verify the output against Portal's startup log, then use it for pin=<sha256>:

./target/release/nowhere fingerprint "nowhere://<generated-key>@portal.example:2000"

5. Start Vector

Connect to Portal and expose SOCKS5 on 127.0.0.1:1080:

./target/release/nowhere \
  "vector://<generated-key>@portal.example:2000?up=tcp&down=tcp&pin=<sha256>&socks=127.0.0.1:1080"

6. Inspect

Open the local TUI from another terminal:

./target/release/nowhere tui

Ecosystem

CLIENT

Anywhere
Native Swift client for TCP/UDP, Mux, and Morph.

App Store
DEPLOY

nowhere-sh
Interactive Linux deployment and share links.

Quick start
CONTROL

OpenCtrl
Process control and telemetry over REST/SSE.

API reference
OPERATE

NowhereDash
Web dashboard for telemetry and subscriptions.

Quick start

How it works

 Application
  TCP / UDP
      |
    SOCKS5
      |
      v
+------------+  Uplink carrier   +--------------+  Native `next` uplink   +-------------+
|   Vector   |==================>| Entry Portal |========================>| Next Portal |
|            |<==================|              |<========================| (optional)  |
+------------+  Downlink carrier +--------------+  Native `next` downlink +-------------+
                                         |                                       |
                                 direct or SOCKS5                        direct or SOCKS5
                                         |                                       |
                                         v                                       v
                                  +------------+                          +------------+
                                  |   Target   |                          |   Target   |
                                  +------------+                          +------------+

Endpoint format

Each service URL uses either a compact endpoint for both carriers on one port, or an explicit endpoint that assigns carriers, ports, and address families.

Endpoint Meaning
@*:2000 TLS/TCP and QUIC/UDP on wildcard addresses, port 2000
@*/tcp:2006 TLS/TCP only, IPv4 and IPv6
@*/udp:2017 QUIC/UDP only, IPv4 and IPv6
@*/tcp4:2006/udp6:2017 TLS/TCP on IPv4 and QUIC/UDP on IPv6

Independent directions

up and down accept tcp, udp, or mix. With both carriers available, the default is TCP; mux=1 enables TLS multiplexing.

up ↓ / down → tcp udp mix
tcp TT TQ TT ↔ TQ
udp QT QQ QT ↔ QQ
mix TT ↔ QT TQ ↔ QQ TT ↔ QQ

T means TLS/TCP and Q means QUIC/UDP, with the uplink listed first. mix randomly selects either carrier with equal probability for each flow and may try the alternate route once before commitment. Portal next= applies the same policy independently on each hop.

Data path

The nw2 wire contract is fixed. Product releases follow the protocol compatibility policy.

Carrier bootstrap                 Logical flow

+----------------+                +----------------+----------+-------------+
| AuthFrame      |                | FlowHeader     | Target?  | Payload ... |
| 32 bytes       |                | 5 bytes        | variable | after READY |
+----------------+                +----------------+----------+-------------+
        |                                  |
        +-- TLS: dedicated lane or Mux     +-- TCP: reliable byte stream
        +-- QUIC: first stream only        +-- UDP: UoT or QUIC DATAGRAM

Morph

morph=1 masks the bare TLS/QUIC wire image with a transform derived from the shared key:

TCP  client -> server   [ prelude 64B ][ nonce 12B ][ ChaCha20-XOR(TLS stream) ]
     server -> client                               [ ChaCha20-XOR(TLS stream) ]

UDP  each datagram      [ nonce 12B ][ ChaCha20-XOR(QUIC datagram) ]

Native chaining

A Portal can open the next Nowhere hop directly. Generate independent keys for the relay and origin, replace <relay-key> and <origin-key>, and configure each peer with its hop's key:

nowhere \
  "portal://<relay-key>@:2000?next=<origin-key>@origin.example:2000&up=udp&down=udp"

next is lazy, mutually exclusive with outbound socks, and bounded to seven hops.

Live operations

Nowhere TUI showing live traffic histories, connection and carrier metrics, anonymous access logs, runtime events, filtering, pause, and help

The read-only TUI discovers local Portal and Vector instances. It presents traffic, carrier, process, and anonymized event data without controlling their lifecycle. Third-party clients use the same telemetry contract.

Public deployment

Vector verifies system CA trust and the endpoint host by default. Public deployments can use a CA-issued certificate without a pin:

nowhere "portal://<generated-key>@:2000?tls=2&crt=/etc/nowhere/cert.pem&key=/etc/nowhere/key.pem"
nowhere "vector://<generated-key>@portal.example:2000?socks=127.0.0.1:1080"

Documentation

Guide Covers
Quick start Build, run, and connect
Ecosystem Clients, deployment and control tools, and share links
Configuration Service URLs, options, chaining, and environment variables
Wire protocol Authentication, flows, Mux, and Morph
Security Certificate verification and trust boundaries
Operations Deployment and runtime behavior
Platforms Supported targets and platform differences
Telemetry Local discovery and monitoring integrations

See the documentation index for the complete reference.

Development

Run the standard checks on a supported host:

cargo fmt --all -- --check
cargo test --all-targets --locked
cargo clippy --all-targets --locked -- -D warnings
cargo build --release --locked

On macOS, Apple Container provides the reusable Linux check environment:

./scripts/check-linux.sh

CI covers Linux, macOS, and Windows. Release packaging covers Linux GNU/musl on x86-64 and AArch64, macOS on Apple Silicon, and Windows x86-64 MSVC. Protocol changes must update the wire document and protocol vectors together.

License

Nowhere is licensed under the GNU General Public License v3.0.


© 2026 NodePassProject. All rights reserved.

About

A cross-platform relay that composes TLS/TCP and QUIC/UDP independently for every flow.

Topics

Resources

Security policy

Stars

456 stars

Watchers

27 watching

Forks

Releases

Packages

Contributors

Languages