VPN

VPN: free self-hosted client install

A local vpn client that deploys onto a server you control keeps traffic on hardware you chose instead of a rented commercial fleet. AmneziaVPN does that work as a GPL-3.0 desktop and mobile client: download the current Windows x64 exe from GitHub Releases (or install with winget), open the app, then deploy WireGuard, AmneziaWG, OpenVPN, or another supported protocol onto your VPS.

  • Deploys a self-hosted vpn onto a server you control
  • Windows, macOS, Linux, and Android builds under GPL-3.0
  • Installer links point at GitHub Releases only

By Mist Latch editorial team Current release, published August 21, 2026

Install AmneziaVPN 5.0.1.5

Windows

Paste into PowerShell or Command Prompt:

winget install -e --id AmneziaVPN.AmneziaVPN

Package: winget package AmneziaVPN.AmneziaVPN (YAML-verified in microsoft/winget-pkgs). Prefer AmneziaVPN_*_windows_x64.exe from GitHub Releases when you want the exact tag asset; winget is the first-party package-manager path..

Other Windows commands
GitHub Releases Windows x64 exe
AmneziaVPN_*_windows_x64.exe

Or download the file directly from the official GitHub release:

Download Windows x64 setup (.exe) AmneziaVPN_5.0.1.5_windows_x64.exe · 87.7 MB · August 21, 2026

Windows 10 or later, 64-bit. Prefer AmneziaVPN_*_windows_x64.exe from a Windows-bearing tag (or current) on amnezia-vpn/amnezia-client; use winget install -e --id AmneziaVPN.AmneziaVPN when you already trust that channel.

macOS

Paste into Terminal:

AmneziaVPN_*_macos_x64.pkg

Package: GitHub Releases AmneziaVPN_*_macos_x64.pkg on the same tag as the Windows exe. No Homebrew cask was verified for AmneziaVPN on this review date..

Or download the file directly from the official GitHub release:

Download macOS x64 installer (.pkg) AmneziaVPN_5.0.1.5_macos_x64.pkg · 106 MB · August 21, 2026

macOS with a matching x64 pkg from the current AmneziaVPN release tag. Open the .pkg from GitHub Releases; Gatekeeper prompts use the Amnezia signing identity when present.

Linux

Paste into your terminal:

AmneziaVPN_*_linux_x64.run

Package: GitHub Releases AmneziaVPN_*_linux_x64.run on the same tag. Make executable and run; no Snap/Flatpak package id was verified on this review date..

Other Linux commands

Or download the file directly from the official GitHub release:

Download Linux x64 installer (.run) AmneziaVPN_5.0.1.5_linux_x64.run · 91.9 MB · August 21, 2026

Also on this release: Android 11+ arm64 (.apk)

A 64-bit Linux desktop. Download AmneziaVPN_*_linux_x64.run, chmod +x, then run. Android APKs for several ABIs ship on the same tag as supporting mobile assets.

Every file comes from amnezia-vpn/amnezia-client 5.0.1.5 on GitHub, the project's own release, unmodified.

Abstract tunnel ring with concentric paths and an umber arc on cool fog paper.
Tunnel-arc mark: flat ink rings with one umber hop for a local self-hosted vpn client install. Mist Latch original hop-pipe geometry for factory-vpn (not an Amnezia logo).

People searching for a vpn usually want a client they can install and trust, not another advertising page that wraps a commercial seat. Keep this vpn install on GitHub Releases for amnezia-vpn/amnezia-client when you want a named vpn binary or on the verified winget id, prove one tunnel on a server you control, then tune protocols only after that path works.

Here vpn means software that encrypts traffic through a tunnel you operate, typically on a VPS you rent and administer. AmneziaVPN is the GPL-3.0 product this guide maps. Source and downloads live on amnezia-vpn/amnezia-client. The release door is GitHub Releases. Safe download path: download-safe path. Repo layout: GitHub overview. Which file: releases.

What a VPN job needs

A vpn job on a personal PC needs software that can open a tunnel, keep keys on hardware you understand, and leave managed commercial fleets for people who want a monthly seat instead. You choose a local client, keep sources on Releases, and avoid surprise toolbars mid-setup. A desktop client for self-hosting reduces account logins that only work while a vendor subscription stays paid.

AmneziaVPN keeps that work on your machine and your server. You install once, deploy containers over SSH when you want a fresh server, pick a protocol, and leave the client running. The everyday win is fewer half-finished “best vpn” download pages than chasing a new commercial brand for every trip.

GPL-3.0 builds

The project license on GitHub reports GPL-3.0. Free open-source downloads cover the Windows x64 exe, macOS pkg, Linux .run, and Android APKs on the same tag. Safety notes: is it safe.

GitHub Releases door

Windows AmneziaVPN_*_windows_x64.exe, macOS pkg, and Linux .run ship together on a verified Windows-bearing tag. Prefer those exact names from AmneziaVPN releases.

Self-hosted first

The product deploys vpn containers onto a server you provide. That is the everyday self-hosted toolkit without a mandatory commercial seat.

  • Prefer GitHub Releases over adware “vpn download” portals.
  • Prefer winget id AmneziaVPN.AmneziaVPN when you already trust that channel.
  • Expect to bring a VPS or existing server for the self-hosted path.
  • Document protocol choice after the first successful tunnel.

Why this desktop path

Self-hosted tunnel work fails when the installer comes from a renamed mirror and the server credentials never get written down. AmneziaVPN from Releases keeps filenames stable enough to put on a ticket: Windows exe, macOS pkg, Linux .run, Android APKs. winget mirrors the same product id when you want a package-manager door.

Commercial subscription apps still win when you want a managed fleet and support chat. Plain WireGuard still wins when you already script configs by hand. Choose this vpn path when you want a GPL-3.0 client that can stand up Docker-based services on a server you SSH into.

A newer tag shipped Linux, macOS, and Android without a Windows exe on the day this guide checked the API. Prefer a Windows-bearing tag such as the verified Windows-bearing release for the primary AmneziaVPN_*_windows_x64.exe asset.

Install by operating system

Match the OS tab in the panel above. Windows prefers the x64 exe or winget. macOS prefers the x64 pkg. Linux prefers the x64 .run. Android APKs sit on the same tag as supporting mobile assets.

OSPrimary doorAlternateNotes
WindowsAmneziaVPN_*_windows_x64.exewinget install -e --id AmneziaVPN.AmneziaVPNPrefer Windows-bearing tags
macOSAmneziaVPN_*_macos_x64.pkgSame Releases tagNo brew cask verified here
LinuxAmneziaVPN_*_linux_x64.runchmod +x then runNo Snap id verified here
AndroidABI-matched .apkandroid11+ or android9-10 buildsSupporting mobile assets

Longer OS paths: Windows, macOS, Linux, Android. Machine chooser: for this computer.

Eight steps to first tunnel

  1. Open GitHub Releases for amnezia-vpn/amnezia-client Open the official Releases page and confirm you are on a stable tag that still ships AmneziaVPN_*_windows_x64.exe for this vpn path, not a renamed mirror setup from a review portal.
  2. Download the Windows x64 exe first Prefer AmneziaVPN_*_windows_x64.exe for a normal Windows vpn client install. A newer tag is the verified Windows-bearing release used in this guide when newer tags omit the exe.
  3. Or install with winget when you trust that channel Run winget install -e --id AmneziaVPN.AmneziaVPN after the package id is confirmed in microsoft/winget-pkgs. Keep one door per machine so updates stay honest.
  4. Confirm AmneziaVPN opens Launch AmneziaVPN so the client window appears before you deploy a server or import a config for this vpn job.
  5. Deploy your own server or import a config Enter a server IP with SSH credentials so Amnezia can install vpn containers, or import an existing supported configuration when you already have one.
  6. Pick a protocol and prove the tunnel Choose WireGuard, AmneziaWG, OpenVPN, or another supported protocol, then confirm the vpn tunnel comes up with a quick site check.
  7. Keep one update door Return to the same GitHub Releases filename or the same winget id for the next bump. Skip Softonic-style wrappers that only rank for vpn.
  8. Optional split tunneling later After the tunnel works, add split-tunnel site or app rules if you need them. Document the protocol and server on the machine ticket.

First hour checklist: installed. First-run habits: first run.

First hour after install

Success is a tunnel that comes up on a server you control, not three download folders full of renamed setups. Launch AmneziaVPN, deploy or import, pick a protocol, then prove one site through the tunnel before you add split-tunnel rules.

SmartScreen or Gatekeeper prompts are common on first launch. Prefer the Releases URL or winget command you typed yourself. Safety overview: is it safe. Self-host detail: self-host server.

How to choose a VPN client

Choose a self-hosted client when you can rent a VPS, keep SSH credentials safe, and accept that you are the operator. Choose a commercial subscription when you want someone else to run the fleet. Choose plain WireGuard when you already maintain configs without a deploy UI.

  • Self-hosted AmneziaVPN: GPL-3.0 client, your server, protocol menu including AmneziaWG
  • Commercial apps: monthly seat, managed servers, usually closed source
  • DIY WireGuard or OpenVPN: maximal control, more manual steps

Switch habits: switch from commercial vpn apps. Comparison: vs commercial vpn apps.

AmneziaVPN compared with other VPN options

OptionPrice modelOpen sourceSelf-hostBest when
AmneziaVPNFree client; you pay for a VPSYes (GPL-3.0)YesYou want deploy UX onto your server
Commercial subscription appsMonthly seatUsually noNoYou want a managed fleet
Plain WireGuard toolsFreeProtocol yesDIYYou already script configs
OpenVPN ConnectFree clientVariesDIYYou already run classic OpenVPN

This comparison is for people who typed the head term and need an honest fork in the road. It is not a ranking of commercial brands. More detail: vpn vs commercial.

Free client vs paid seats

AmneziaVPN itself is free under GPL-3.0. Your cost is the VPS and the time to keep SSH access healthy. Optional premium offerings mentioned upstream are separate from the self-hosted client path this guide maps. Commercial seats bundle servers you never SSH into; price that model when you do not want to be the operator.

Mistakes that undo a VPN install

  • Grabbing a Softonic-style setup that renames the binary
  • Expecting a managed commercial fleet without deploying a server
  • Mixing winget and a second mirror installer on one PC
  • Assuming every newer tag still ships the Windows exe
  • Skipping notes about which protocol and server IP you chose

Fix each mistake the same way: one honest door, one proven tunnel, one documented path. Troubleshooting habits live in the guides hub.

Guides index

Install guides cover Windows, macOS, Linux, and Android. Setup guides cover first run, self-host deploy, split tunneling, and update/uninstall. Comparison and switch pages help when a commercial app is already installed. Browse all: guides.

Repeatable desk habits

Write the update door on the machine ticket beside the OS version. Windows exe, winget, macOS pkg, Linux .run, and Android APK are different doors. Mixing them without notes creates duplicate installs and confused uninstalls after a reimage.

Family PCs, travel laptops, and lab images all benefit from the same boring rhythm: one installer door, one server record, one documented protocol. That is how a self-hosted vpn habit stays boring for everyday vpn desks in a good way.

Everyday limits

AmneziaVPN does not replace careful SSH hygiene. It does not make a cheap VPS into a global commercial anycast network. It does not remove the need to trust the server image you deploy onto. Offline use still needs network for the first download and for server deploy.

Settings that matter early

Protocol choice, split tunneling, and which apps or sites traverse the tunnel matter more than skins. Prove the tunnel before you chase masking options. Split-tunnel guide: split tunnel.

After the first tunnel

Only after one site loads through the tunnel should you add more devices or APKs. Keep Releases bookmarked. Prefer the same tag family that still ships your OS asset. Update guide: update uninstall.

Keeping the job name clear

Here vpn means a self-hosted tunnel client you install and operate. A review portal that only ranks for the head term is still the wrong binary. Prefer AmneziaVPN_*_windows_x64.exe, the matching pkg or .run, or winget id AmneziaVPN.AmneziaVPN, then prove one tunnel before you batch protocols.

When someone pastes a random “best download” link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.

Remember the job name: vpn here means a self-hosted client plus a server you control. A Softonic mirror that only ranks for the head term is still the wrong binary. Prefer the named Releases assets, then prove one tunnel before you add split-tunnel rules.

Paid commercial seats still win when purchasing requires vendor support contracts. Browser-only tunnels still win when install rights are missing. Plain WireGuard still wins for operators who refuse a GUI. Choose AmneziaVPN when you want GPL-3.0 builds, exact Releases names, and a deploy path onto a server you SSH into.

Mist Latch publishes the install guide. Upstream AmneziaVPN remains at amnezia.org and GitHub. When Releases change which OS assets appear on a tag, re-check the live list before you image a lab.

Lab and travel notes

Travel laptops benefit from a single documented installer door written beside the VPS hostname. Lab images drift when someone installs a second mirror during a blocked SmartScreen prompt. Prefer returning to the same Releases URL or the same winget id instead of inventing a new download mid-flight.

Contractors who need a temporary tunnel should receive the client on a machine they control, plus SSH credentials that expire. Shared desks should keep commercial subscription apps available as a fallback until the self-hosted habit sticks for the whole room.

Classroom images should pin the exact filename or package id beside the OS version. After every reimage, prove one short site load through the tunnel before you call the machine ready. That habit catches vanished portable folders and Softonic shortcuts that reappear from old bookmark exports.

Command-line users who already live in WireGuard scripts can keep those scripts. Treat AmneziaVPN as the windowed path for teammates who need a deploy UI. The two can share a VPS when the room documents which path is official for demos.

How do I install a VPN on Windows?

Download the current AmneziaVPN_*_windows_x64.exe from GitHub Releases for amnezia-vpn/amnezia-client and run it, or run winget install -e --id AmneziaVPN.AmneziaVPN when you already trust winget. Prefer a Windows-bearing tag such as the verified Windows-bearing release when newer tags omit the exe. Guide: install on Windows. Keep one door so the next client bump stays honest.

Where should I download a VPN app?

Prefer GitHub Releases for amnezia-vpn/amnezia-client when you need the Windows x64 exe, macOS pkg, Linux .run, or Android APKs. Skip Softonic-style wrappers that rename the setup for a search ranking. Details: download safe. Keep downloads on the project release list so the client binary matches the tag you expect.

Is this VPN software free?

AmneziaVPN is free under GPL-3.0. GitHub Releases assets named above have no paywall for the client. You still pay for any VPS you rent for self-hosting, and optional upstream premium offers stay separate from that client licence. This guide does not sell seats.

Can I switch into this VPN from a commercial app?

Yes. Install AmneziaVPN, deploy or import a config as proof, and keep the commercial app available until the self-hosted tunnel habit sticks. Guide: switch from commercial vpn apps. Comparison context: vs commercial vpn apps. Account seats from commercial apps do not transfer into your VPS.

Does the desktop VPN work offline?

The client can sit installed offline after download, but a working vpn tunnel needs network to reach your server. You still need network for the first download of the exe, pkg, .run, or APK. Offline habits: first run and first hour. A desk install does not require a commercial account.

Official releases

All releases on GitHub
GitHub stars
15,014
Downloads, last 3 releases
1.6M
Latest version
5.0.1.5

Latest

5.0.1.5

5.0.1.5

Counts come from the GitHub API at build time and only cover the * tags shown here. Package managers (winget, Homebrew, Snap, Flathub) and app stores are not included.