One relay. Two carriers. Independent directions.
A cross-platform relay that composes TLS/TCP and QUIC/UDP
independently for every flow.
Quick start · Ecosystem · Architecture · Live operations · Documentation · Wire protocol
Nowhere joins TLS/TCP and QUIC/UDP behind one service edge. Vector accepts local SOCKS5 traffic; Portal authenticates carriers and reaches the target. Each flow selects its uplink and downlink independently.
| Core property | What it means |
|---|---|
| Unified edge | TLS/TCP and QUIC/UDP share one service identity and lifecycle |
| Split routing | Uplink and downlink choose their carrier independently |
| Optional Morph | A keyed transform masks the TLS/QUIC wire image |
| TCP and UDP | SOCKS5 CONNECT and UDP ASSOCIATE are both supported |
| Native chaining | Portal forwards directly to Portal with no local proxy loop |
| Built-in telemetry | The same binary discovers and inspects live instances |
Use a stable Rust toolchain on a supported target, or download a prebuilt binary.
cargo build --release --lockedGenerate a shared key for <generated-key> in both Portal and Vector URLs:
./target/release/nowhere generate-keyListen on TLS/TCP and QUIC/UDP at all interfaces on port 2000:
./target/release/nowhere "portal://<generated-key>@*:2000"Verify the output against Portal's startup log, then use it for pin=<sha256>:
./target/release/nowhere fingerprint "nowhere://<generated-key>@portal.example:2000"Connect to Portal and expose SOCKS5 on 127.0.0.1:1080:
./target/release/nowhere \
"vector://<generated-key>@portal.example:2000?up=tcp&down=tcp&pin=<sha256>&socks=127.0.0.1:1080"Open the local TUI from another terminal:
./target/release/nowhere tui|
CLIENT Anywhere Native Swift client for TCP/UDP, Mux, and Morph. App Store |
DEPLOY nowhere-sh Interactive Linux deployment and share links. Quick start |
|
CONTROL OpenCtrl Process control and telemetry over REST/SSE. API reference |
OPERATE NowhereDash Web dashboard for telemetry and subscriptions. Quick start |
Application
TCP / UDP
|
SOCKS5
|
v
+------------+ Uplink carrier +--------------+ Native `next` uplink +-------------+
| Vector |==================>| Entry Portal |========================>| Next Portal |
| |<==================| |<========================| (optional) |
+------------+ Downlink carrier +--------------+ Native `next` downlink +-------------+
| |
direct or SOCKS5 direct or SOCKS5
| |
v v
+------------+ +------------+
| Target | | Target |
+------------+ +------------+
Each service URL uses either a compact endpoint for both carriers on one port, or an explicit endpoint that assigns carriers, ports, and address families.
| Endpoint | Meaning |
|---|---|
@*:2000 |
TLS/TCP and QUIC/UDP on wildcard addresses, port 2000 |
@*/tcp:2006 |
TLS/TCP only, IPv4 and IPv6 |
@*/udp:2017 |
QUIC/UDP only, IPv4 and IPv6 |
@*/tcp4:2006/udp6:2017 |
TLS/TCP on IPv4 and QUIC/UDP on IPv6 |
up and down accept tcp, udp, or mix. With both carriers available,
the default is TCP; mux=1 enables TLS multiplexing.
up ↓ / down → |
tcp |
udp |
mix |
|---|---|---|---|
tcp |
TT | TQ | TT ↔ TQ |
udp |
QT | QT ↔ QQ | |
mix |
TT ↔ QT | TQ ↔ QQ | TT ↔ QQ |
T means TLS/TCP and Q means QUIC/UDP, with the uplink listed first. mix
randomly selects either carrier with equal probability for each flow and may
try the alternate route once before commitment. Portal next= applies the same
policy independently on each hop.
The nw2 wire contract is fixed. Product releases follow the protocol compatibility policy.
Carrier bootstrap Logical flow
+----------------+ +----------------+----------+-------------+
| AuthFrame | | FlowHeader | Target? | Payload ... |
| 32 bytes | | 5 bytes | variable | after READY |
+----------------+ +----------------+----------+-------------+
| |
+-- TLS: dedicated lane or Mux +-- TCP: reliable byte stream
+-- QUIC: first stream only +-- UDP: UoT or QUIC DATAGRAM
morph=1 masks the bare TLS/QUIC wire image with a transform derived from the
shared key:
TCP client -> server [ prelude 64B ][ nonce 12B ][ ChaCha20-XOR(TLS stream) ]
server -> client [ ChaCha20-XOR(TLS stream) ]
UDP each datagram [ nonce 12B ][ ChaCha20-XOR(QUIC datagram) ]
A Portal can open the next Nowhere hop directly. Generate independent keys for
the relay and origin, replace <relay-key> and <origin-key>, and configure
each peer with its hop's key:
nowhere \
"portal://<relay-key>@:2000?next=<origin-key>@origin.example:2000&up=udp&down=udp"next is lazy, mutually exclusive with outbound socks, and bounded to seven
hops.
The read-only TUI discovers local Portal and Vector instances. It presents traffic, carrier, process, and anonymized event data without controlling their lifecycle. Third-party clients use the same telemetry contract.
Vector verifies system CA trust and the endpoint host by default. Public deployments can use a CA-issued certificate without a pin:
nowhere "portal://<generated-key>@:2000?tls=2&crt=/etc/nowhere/cert.pem&key=/etc/nowhere/key.pem"
nowhere "vector://<generated-key>@portal.example:2000?socks=127.0.0.1:1080"| Guide | Covers |
|---|---|
| Quick start | Build, run, and connect |
| Ecosystem | Clients, deployment and control tools, and share links |
| Configuration | Service URLs, options, chaining, and environment variables |
| Wire protocol | Authentication, flows, Mux, and Morph |
| Security | Certificate verification and trust boundaries |
| Operations | Deployment and runtime behavior |
| Platforms | Supported targets and platform differences |
| Telemetry | Local discovery and monitoring integrations |
See the documentation index for the complete reference.
Run the standard checks on a supported host:
cargo fmt --all -- --check
cargo test --all-targets --locked
cargo clippy --all-targets --locked -- -D warnings
cargo build --release --lockedOn macOS, Apple Container provides the reusable Linux check environment:
./scripts/check-linux.shCI covers Linux, macOS, and Windows. Release packaging covers Linux GNU/musl on x86-64 and AArch64, macOS on Apple Silicon, and Windows x86-64 MSVC. Protocol changes must update the wire document and protocol vectors together.
Nowhere is licensed under the GNU General Public License v3.0.
© 2026 NodePassProject. All rights reserved.

