English · Русский · Español · 中文 · فارسی · العربية
Proxy client for sing-box, xray-core and mihomo
Your own VLESS, Trojan, Shadowsocks and WireGuard servers, routed from the browser.
Important
Noctis routes the browser it is installed in, not the whole machine — the rest of your OS keeps its own connection. The extension is free under a proprietary EULA; the native helper is open source (MIT).
Noctis is a free proxy client for VLESS, VMess, Trojan, Shadowsocks, Hysteria2, TUIC, WireGuard and more. It holds your servers, your subscriptions and your routing rules, and starts whichever of the three engines a server needs. Today it ships as a Chrome extension with a local helper: the extension is the control panel, the helper supervises the engine.
- Three engines, one per server — sing-box, xray-core and mihomo ship together and Noctis picks the one each server needs: sing-box runs every protocol it reads, xray-core is the only engine that builds xhttp, and mihomo runs sing-box's set without ShadowTLS.
- Servers from share links, QR, or subscription URLs — Paste
vless://,vmess://,trojan://,ss://,hysteria2://,tuic://,wireguard://— or scan a QR code. Subscription URLs auto-refresh on a schedule. - Per-rule routing — Match by domain, GeoSite, or GeoIP. Each rule routes to proxy, direct, or block.
- Three routing modes — Global sends everything through the proxy. Rules only routes matches. Direct bypasses entirely.
- Health checks + automatic failover — Background latency probes; one-tap manual ping per server. Failing servers drop out of the active route.
- Pinned-server shortlist — Keep three favorites at the top of the popup. Switch active server without opening the full panel.
- Live log stream — the proxy engine's stdout and stderr stream into the extension. Diagnose connection issues without leaving the browser.
- Backup and transfer — Export servers, subscriptions, profiles and preferences to one JSON file, and import that file back. A single routing profile also saves to a file of its own, so a rule set moves between browsers or machines without retyping it.
- WebRTC leak guard — Optional toggle blocks UDP outside the proxy so WebRTC can't reveal your real IP.
- Ad and tracker blocking in one rule — The
category-ads-allfamily sits in the Geosite field's suggestions. Add it to the Block group and the profile drops ads and trackers.
VLESS · VLESS Reality · VMess · Trojan · Shadowsocks · Hysteria/2 · TUIC · WireGuard · AnyTLS · ShadowTLS
Noctis supports VLESS (including VLESS Reality), VMess, Trojan, Shadowsocks, Hysteria2, TUIC, WireGuard, AnyTLS and ShadowTLS. Configs from V2Ray, Xray and 3X-UI panels work as-is — paste a share link or subscription URL and the extension translates it into the right engine's config automatically. Every engine accepts TLS, Reality and the XTLS vision flow; xhttp is xray-core's alone.
Browsers can't run a proxy engine on their own. Three pieces split the work across the sandbox boundary — and the arrow that crosses it is the only place messages flow.
Browser Your machine
┌──────────────────┐ native messaging ┌──────────────────┐
│ Noctis extension │ ◀─────────────────▶ │ noctis-host │
│ popup · panel │ events · logs │ (native helper) │
│ options │ └────────┬─────────┘
└────────┬─────────┘ │ spawn · config
│ ▼
│ ┌──────────────────┐
│ Chrome proxy → SOCKS/HTTP │ proxy engine │
└───────────────────────────────▶│ │
└────────┬─────────┘
│ encrypted
▼
┌──────────────────┐
│ Proxy servers │
└──────────────────┘
Noctis ships sing-box, xray-core and mihomo together. A small native helper supervises the engine on your machine, and Noctis picks the one each server needs: sing-box runs every protocol Noctis reads, xray-core is the only engine that builds xhttp, and mihomo runs sing-box's set without ShadowTLS. The browser extension only ever sends routing decisions — never raw traffic.
A routing profile is three groups of rules plus the order they are checked in. The Evaluation order chips on the profile screen show that order, and you can drag them.
| Group | What happens to a match |
|---|---|
| Direct | Leaves through your real connection, skipping the proxy. |
| Proxy | Leaves through the active server. |
| Block | The request is dropped. Noctis shows its own block page and names the rule that matched. |
The first match wins, so the order settles conflicts. With the default Direct → Proxy → Block, a host listed in Direct and in Block goes direct.
Each group takes three kinds of entries: Domains (example.com, *.example.com), Geosite (a category name such as youtube or ads), Geoip (a country code such as cn, or a CIDR range).
Anything that matches no group goes direct. Groups only apply in Rules mode: Global sends all traffic through the proxy, Direct skips the proxy entirely.
Block drops traffic instead of routing it: ad and tracker domains, telemetry endpoints, a site you do not want opening in this browser. A new profile starts empty, since Noctis adds no rules of its own. To drop ads, add the category-ads-all family to Block; the Geosite field offers it as a suggestion. If a page turns out blocked unexpectedly, the block page names the profile and the rule, and lets you remove it from there.
The Noctis extension needs a small native helper running on your machine. The helper supervises the proxy engine — sing-box, xray, or mihomo — that actually does the proxying.
- A Chromium-based browser, version 120 or newer (Chrome, Chromium, Edge, Brave, Arc, Vivaldi, Opera, Yandex Browser).
- About 100 MB of free disk for the helper and the proxy engines.
- No admin / root rights — everything installs into your user account.
Install Noctis from the Chrome Web Store. Open the extension after install — it will detect that the helper is missing and show a setup dialog with a one-liner pre-filled for your machine.
Copy the command from the extension's Helper Setup dialog and paste it into your terminal. Your extension ID is already filled in — you don't need to look it up. For reference, the command looks like this:
Helper source: host/
macOS
curl -fsSL https://noctis.c0nn3ct.info/macos.sh | bash -s -- nmhobajopepdpihahepaddpdifdcenpnLinux
curl -fsSL https://noctis.c0nn3ct.info/linux.sh | bash -s -- nmhobajopepdpihahepaddpdifdcenpnWindows (PowerShell)
$env:NOCTIS_EXT_ID='nmhobajopepdpihahepaddpdifdcenpn'; iwr -useb https://noctis.c0nn3ct.info/windows.ps1 | iexThe installer downloads noctis-host and the proxy engines (sing-box, xray, mihomo) into your user data directory and writes a native-messaging manifest for every supported browser.
Running it from more than one browser or profile is fine: each browser's extension has its own id, and the installer accumulates ids in the manifest rather than replacing them. So if you use Noctis in several browsers or profiles at once, just run the Helper Setup command shown in each — every one stays connected, and each can run its own server simultaneously.
The first time the extension talks to the helper, your browser may show a one-time native-messaging prompt — approve it.
Open the extension's popup, paste a vless://, ss://, or trojan:// share link (or a subscription URL), and toggle the active server. The status badge turns green once the engine accepts traffic.
Rerun the one-liner for your OS — the script is idempotent and will replace the existing binaries.
- Remove the extension from
chrome://extensions. - Delete the Noctis data directory:
- macOS / Linux:
~/.local/share/noctis - Windows:
%LOCALAPPDATA%\Noctis
- macOS / Linux:
What is VLESS and why use it in a browser? VLESS is a lightweight proxy protocol from the V2Ray/Xray family. It carries no encryption of its own — TLS does that — so it's fast and easy to disguise as ordinary HTTPS. Using VLESS through a browser extension means only browser traffic is proxied; the rest of your operating system stays on your real connection.
How is a browser proxy extension different from a VPN? A VPN tunnels every app on your system through one connection and usually needs admin rights. A browser proxy extension like Noctis only routes the browser, requires no root or admin, and lets you keep Zoom, Steam, Telegram desktop and torrents on your real network at the same time.
Does Noctis support VLESS Reality?
Yes. Noctis passes Reality parameters (Server Name, Fingerprint, SNI, Dest, public key, short ID) through to the helper unchanged and runs the server on an engine that supports it — xray drives the full XTLS-vision flow. Paste a vless://...flow=xtls-rprx-vision&security=reality share link and the extension imports every field.
Which proxy protocols does Noctis support? VLESS, VMess, Trojan, Shadowsocks, Hysteria/2, TUIC, WireGuard, AnyTLS, ShadowTLS, SOCKS and HTTP — over tcp, ws, grpc, httpupgrade, http or xhttp, with TLS, Reality or the XTLS vision flow. V2Ray and Xray share links work as-is.
Is a Chrome proxy extension safe to use? Safer than most. Noctis sends nothing to its developer — no analytics, no telemetry, no remote config. Server configs stay in browser storage. The native helper runs without admin rights. The full permission list and rationale is in the privacy policy.
Does Noctis work on Windows, macOS and Linux? Yes — Chromium-based browsers on Windows, macOS and Linux (Chrome, Edge, Brave, Arc, Vivaldi, Opera, Yandex Browser). The native helper has one-line install scripts for each platform.
Can I use a subscription URL to auto-update servers? Yes. Paste a subscription URL once and Noctis refreshes it on a schedule. Server lists update automatically; pinned and active selections survive refreshes.
Will Noctis help bypass website blocks? Noctis itself is just a proxy client — it routes your browser through whatever server you provide. If your server is in a region where the site you want to reach is accessible, Noctis routes you there. It does not provide servers; you supply them.
Does Noctis block WebRTC leaks? Yes. An optional toggle blocks UDP outside the proxy so WebRTC can't reveal your real IP while the proxy is active.
How much does Noctis cost? Free. The extension is free in the Chrome Web Store and the native helper is open-source under MIT. You only pay for the proxy servers you choose to use.
What does the Block section in a routing profile do? Block drops matching requests instead of sending them anywhere - no proxy, no direct connection. Noctis shows its own block page and names the rule that matched. See Routing rules for the full chain.
- sing-box (GPL-3.0), xray-core (MPL-2.0) and mihomo (GPL-3.0) — the proxy engines that do all upstream routing and encryption. Noctis is a control surface; the engine does the actual work, and Noctis auto-picks the right one per server.
- V2Ray and Xray — the upstream protocol designs (VLESS, VMess, Reality) that Noctis speaks.
- License — proprietary EULA: see LICENSE or https://noctis.c0nn3ct.info/license/.
- Privacy — see PRIVACY or https://noctis.c0nn3ct.info/privacy/.
- Native helper — MIT-licensed: see
host/. - Proxy engines — sing-box (GPL-3.0), xray-core (MPL-2.0) and mihomo (GPL-3.0), each redistributed under its upstream license.