What Is VLESS? Protocol, REALITY, Clients, and Setup Explained
Technical Editorial Team · Published February 19, 2026 · Updated September 30, 2026
VLESS is a proxy protocol in the V2Ray/Xray ecosystems used to identify clients and carry proxy requests. It is not a VPN client, and the protocol name alone cannot tell you whether a connection is secure, fast, or available. You also need to consider its transport, security settings such as TLS or REALITY, and how the client captures traffic.
We'll start with the components of a connection, then cover common combinations, client choices, and differences between VLESS, VMess, and Shadowsocks.
Where Does VLESS Fit in V2Ray/Xray?
V2Ray is a proxy platform. Xray grew out of V2Ray and continues to expand protocol and transport capabilities. VLESS operates between client and server: the client sends a user identifier and destination address, and the server verifies the identifier before forwarding the request. Client mode and routing rules determine which apps use the proxy.
VLESS commonly uses a UUID as the user identifier, and authentication does not depend on the device clock. “Stateless” describes the protocol design; it does not imply that the server keeps no access logs or that users are completely anonymous.
What Do Protocol, Transport, and Security Settings Each Do?
A server profile is easier to understand in parts: VLESS handles proxy requests; RAW, WebSocket, XHTTP, gRPC, and other transports carry the data; TLS or REALITY handles connection security and the handshake. Routing rules, system proxy settings, and TUN mode determine how device traffic enters the client.
Check these layers together. Seeing “VLESS” does not tell you whether a server uses TLS, or whether apps other than the browser will use the proxy.
Common profiles set VLESS encryption to none and protect the connection with outer TLS or REALITY. This does not mean the whole connection is unencrypted. Newer Xray versions also offer optional VLESS Encryption; both client and server must support it. “VLESS itself never has encryption” is therefore not a universal rule.
How Do You Read Common VLESS Combinations?
- VLESS + RAW + TLS: Carries data directly over TCP, with TLS protecting the connection.
- VLESS + RAW + REALITY: Uses REALITY for the handshake and security, with a setup different from ordinary TLS certificate deployment.
- VLESS + WebSocket + TLS: Carries data over WebSocket, often for deployments needing a web entry point or CDN compatibility. A particular CDN must support the chosen configuration.
- VLESS + XHTTP + REALITY: Uses another HTTP transport. Client and server versions and the specific mode must be compatible.
These are configuration examples, not performance rankings. Read What Is REALITY? for handshake details, or VLESS and CDNs for CDN limitations.
For a closer look at security and transport choices, see REALITY vs TLS and XHTTP vs WebSocket vs gRPC.
How Are REALITY and VLESS Related?
VLESS handles proxy requests. REALITY establishes a protected connection and shapes the handshake's appearance. Ordinary TLS deployments usually need a server certificate; REALITY uses a different handshake and verification mechanism, so profiles include target names, key parameters, and short IDs.
Client parameters must match the server. REALITY does not hide the destination IP, traffic volume, or connection timing, and cannot guarantee permanent availability. It addresses one part of the connection; see VLESS and REALITY Explained for the full process.
How Do VLESS, VMess, and Shadowsocks Differ?
VMess handles encryption at the protocol layer; common VLESS configurations use TLS or REALITY for transport protection. Shadowsocks encrypts within its protocol and has a different configuration model. No protocol name alone proves a connection is faster or more secure: route quality, transport, security, and client matter too. See VLESS vs. VMess and VLESS vs. Shadowsocks for details.
How Do You Choose a Client and Connection Mode?
First identify your platform, then whether you have a VLESS server link, a subscription URL, or a Mihomo or sing-box configuration file. Clients accept different formats. Consider v2rayN for Windows and v2rayNG for Android; other options suit iPhone, Mac, and rule-based routing. The client comparison table can narrow your choices by platform.
- Get a server profile or subscription configuration suited to your client from the provider, and import it using the client's instructions.
- Select a server and check that transport and security parameters were imported too. Do not enter only the address and UUID.
- Enable system proxy, VPN, or TUN mode as needed, then test the apps and websites you actually plan to use.
Even after the client shows “Connected,” test the destination website. If something fails, check server reachability, DNS, and routing rules separately. For the distinction between proxy and VPN modes, read How Does V2Ray Differ from a Traditional VPN?.
If you use WahooVPN and want to import your subscription into another client, follow the third-party app import guide to create a link in the right format. Still choosing an app? Compare the five VLESS clients by platform first, then check the subscription format and your server's transport and security settings.
For manual setup, consult Xray's VLESS configuration documentation and transport configuration documentation. Use each core's own documentation for its fields and supported features.