Trojan
Trojan authenticates each user by password and relies on TLS for everything else. It is widely supported, simple to set up, and a good second protocol beside VLESS, especially over WebSocket behind a CDN.
What it is good for
- Apps that default to it. Many apps offer Trojan first, and almost all of them read it.
- A CDN-fronted inbound. Inbounds → From a preset → Trojan + WebSocket + TLS gives you one ready for a domain front.
Create it
Start from the preset above, or Inbounds → Add and type trojan. See Inbounds for the general form.
| Tab | What to set |
|---|---|
| Basic | Port |
| Transport | tcp (none), or ws, grpc, httpupgrade, xhttp… |
| TLS | TLS with a Certificate (usually Node certificate), or REALITY |
| Multiplex | optional, for sing-box and Clash apps that multiplex |
Each user signs in with the Password on their Credentials tab, which the panel generates for every account.
TLS is the protection
Trojan's own security is TLS. The form lets you pick None, and that is right in exactly two places:
- Behind an ingress that terminates TLS for it.
- Behind a CDN that terminates TLS and talks plain HTTP to your node.
Anywhere else, an inbound with no TLS sends your users' passwords and traffic in the clear.
With a self-signed certificate (the node's own, for example), the panel puts the certificate's pin into every link and subscription file, so apps trust it without a public authority. See Certificates.
Behind a CDN
With a ws, grpc, httpupgrade, xhttp or http transport and TLS or no TLS (never REALITY), a front can carry it. See Domain fronting.
Client apps
| Format | |
|---|---|
Share link (trojan://) | yes |
| Clash apps | yes, except the quic, xhttp and mkcp transports |
| sing-box apps | yes, except xhttp and mkcp |
| Xray-based apps | yes, except http (HTTP/2) and quic |
Related
- Protocols — every protocol compared
- Domain fronting — putting it behind a CDN
