Skip to content
HIDDENIO

TROJAN

Password-authenticated protocol disguised as ordinary HTTPS traffic.
Open as feed
Records
974
Countries
48
Compatible clients
11

About TROJAN

Trojan disguises proxy traffic as normal HTTPS: the client performs a standard TLS handshake with a certificate that looks like any website's, then authenticates with a password inside the encrypted channel. There is no recognizable handshake fingerprint, which was its original advantage against protocol detection. Trojan supports TLS, WebSocket and gRPC transports and accepts SNI camouflage hosts. Because it always expects TLS, plain-text Trojan links do not exist in practice.

Top countries

Counts reflect the country codes observed on TROJAN records. Follow a row to the protocol-country combination.

Frequently asked questions

What is Trojan?

Trojan is a proxy protocol that disguises traffic as ordinary HTTPS. A record contains a password, a server address and TLS settings such as SNI.

What does freshness mean for Trojan records?

Freshness is when a record was last observed in a public source. It is not an availability check — a fresh record can still be offline.

How are Trojan records deduplicated?

Records with the same protocol, address, port and credentials are merged, and their source observations are combined into one history.

Freshness shows when a config was last seen in a public source — not whether it works.