Skip to content
HIDDENIO

What Is Hysteria2?

Hysteria2 is a QUIC-based proxy protocol focused on poor-network performance, using a password-authenticated UDP transport.

Last reviewed: Sep 28, 2026, 05:52 AM

Overview

Hysteria2 is a proxy protocol built on QUIC, the UDP-based transport underneath HTTP/3. It was redesigned from the original Hysteria to behave like HTTP/3 as much as possible: the connection uses a standard TLS 1.3 handshake over UDP, and authentication is a simple password in the URI. Its defining feature is a brutal congestion-control mode that intentionally saturates a link instead of backing off, which helps on lossy or throttled paths where TCP-based protocols collapse.

Anatomy of a hysteria2:// link

Hysteria2 share links are deliberately simple:

  • Auth string - the password, placed where a username would sit.
  • Host and port - typically a UDP port such as 443.
  • `sni` - the server name for the TLS handshake.
  • `insecure` - skips certificate verification when set.
  • `obfs` - optional Salamander obfuscation that disguises QUIC traffic.

You can decode any of these with the config parser.

Strengths and costs

Because it runs over UDP, Hysteria2 avoids TCP head-of-line blocking and recovers from packet loss quickly, often outperforming WebSocket or gRPC tunnels on bad networks. The trade-off is that some networks rate-limit or block UDP entirely, in which case a TCP-based protocol such as Trojan or VLESS may be the only option. The aggressive congestion mode can also be unfair to other traffic sharing the same link.

Limitations

insecure=1 links skip TLS verification and are vulnerable to interception; prefer verified endpoints when possible. Hysteria2 support in client apps is common but not universal - check the client directory before importing. HiddenIO indexes public sources and cannot guarantee that any Hysteria2 endpoint works or is safe to use.