What Is VLESS?
VLESS is a lightweight stateless proxy protocol used as a successor to VMess, best known for its minimal handshake and REALITY TLS camouflage.
Última revisión: 28 sept 2026, 05:52 · originally in EN
Overview
VLESS is a protocol designed for the Xray proxy ecosystem. It was created as a leaner alternative to VMess: unlike its predecessor, VLESS performs no built-in encryption of its own and instead relies entirely on the transport layer, typically TLS or REALITY. That makes the handshake shorter and the CPU cost per connection lower, since the heavy cryptography is delegated to a well-audited TLS stack.
How a VLESS config is structured
A VLESS endpoint is distributed as a URI with a UUID as the credential. The important parts of the link are:
- UUID - identifies the user account on the server.
- Transport (`type`) - how traffic is carried:
tcp,ws(WebSocket),grpc, orhttpupgrade. - Security (`security`) -
none,tls, orreality. - SNI and host - the server name presented during the TLS handshake.
- Flow - optional processing modes such as
xtls-rprx-visionused with REALITY.
You can paste any VLESS link into the config parser to see every field it contains explained field by field.
Why it became popular
Two properties drive adoption. First, VLESS with REALITY can mimic an ordinary TLS connection to a real, unrelated website, which makes blanket protocol filtering harder. Second, the protocol adds almost no overhead of its own, so throughput is close to what the transport allows. Most modern clients listed in our tools directory accept VLESS links directly or via subscription feeds.
Limitations
VLESS by itself is only a wire format; security depends on the transport chosen. A security=none link sends traffic in clear text and should be avoided. HiddenIO indexes configurations found in public sources and cannot guarantee that any endpoint works, is trustworthy, or is safe to route your traffic through - review what you import and use endpoints at your own risk.