What Is REALITY?
REALITY is a TLS camouflage mechanism used with VLESS that borrows the certificate of a real website instead of using its own.
Última revisión: 28 sept 2026, 05:52 · originally in EN
Overview
REALITY is not a standalone protocol but a security layer for VLESS. A conventional TLS proxy must present its own certificate, which immediately marks the connection as proxy-related if the certificate does not match a real site. REALITY solves this by borrowing the TLS handshake and certificate of a genuine, third-party website: to an observer the connection looks like ordinary traffic to that site, and only a client holding the correct public key can complete the inner VLESS session.
What appears in a REALITY config
REALITY links carry a few distinctive query parameters:
- `security=reality` - selects the REALITY layer.
- `pbk` - the server's public key, used to authenticate the handshake.
- `sid` - a short ID that disambiguates server configurations.
- `sni`/`peer` - the real website whose certificate is borrowed.
- `fp` - the TLS fingerprint the client should imitate, such as
chrome. - `flow` - usually
xtls-rprx-vision, which reduces double encryption.
Paste any REALITY link into the config parser to see these fields decoded.
Why it matters
Because the proxy never owns a certificate, blocks based on certificate transparency logs or self-signed fingerprints do not apply. Active probing is also harder: an unauthenticated probe is answered by the borrowed website's genuine TLS behaviour, not by proxy software. This combination has made VLESS-REALITY the default choice for newly published configs in many subscriptions.
Limitations
REALITY hides the protocol fingerprint; it does not authenticate the operator. A malicious endpoint still sees your traffic after decryption, and borrowed certificates can be revoked or change at any time. HiddenIO indexes REALITY configurations from public sources and cannot guarantee that any endpoint works, remains online, or is safe to use.