الانتقال إلى المحتوى
HIDDENIO

What Is VMess?

VMess is the encrypted request-response proxy protocol of the V2Ray project, distributed as base64-encoded JSON share links.

آخر مراجعة: 28 سبتمبر 2026، 05:52 ص · originally in EN

Overview

VMess is the original protocol of the V2Ray project. Unlike plain proxy protocols, VMess builds encryption and authentication into the protocol itself: every request is authenticated with the user's UUID and encrypted with a negotiated cipher before it leaves the client. It predates VLESS and remains one of the most widely deployed protocols in public config lists.

The share-link format

VMess endpoints are almost always shared as vmess:// links whose body is base64-encoded JSON. The JSON object carries the server address, port, user ID (UUID), alter ID, encryption setting and transport options. Because the payload is JSON rather than a query string, the same endpoint can express many extra fields such as HTTP camouflage hosts. Our base64 decoder and config parser both unwrap these links so you can inspect them before use.

Transports and features

A VMess server can be reached over several transports:

  • TCP - the simplest mode, sometimes with HTTP camouflage headers.
  • WebSocket (`ws`) - tunnels traffic through a WebSocket, which works behind CDNs.
  • gRPC and HTTP/2 - multiplexed transports useful in restrictive networks.

Alter IDs were used for anti-replay but are deprecated in modern servers and set to zero; older configs may still carry the field.

VMess versus VLESS

The practical difference is where encryption happens. VMess encrypts inside the protocol; VLESS relies on TLS or REALITY and skips its own crypto layer. VMess remains fully usable and is supported by every client in the ecosystem, which is why it still dominates older public subscriptions.

Limitations

Encryption inside the protocol does not mean a server is honest. Public VMess configs can log, throttle or intercept your traffic. HiddenIO indexes public sources only and cannot guarantee that any listed endpoint works or is safe; treat every imported configuration as untrusted until you have verified it.