VPN

VPN: self-hosted client vs commercial apps

By Mist Latch editorial team Current release, published August 21, 2026

Close detail of hop-pipe geometry used as the vpn mark.
Tunnel detail for the vpn mark used across this install guide. Mist Latch original hop-pipe geometry for factory-vpn (not an Amnezia logo).

A self-hosted vpn client under GPL-3.0 (AmneziaVPN) aims at servers you operate. Commercial subscription apps sell managed fleets. Pick based on whether you want to run the server.

FactorAmneziaVPNCommercial apps
PriceFree client; you pay for a VPSMonthly seat
SourceGPL-3.0 on GitHubUsually closed
ServersYoursVendor fleet
SupportCommunity + docsVendor support desks
Best whenYou can SSH and maintain a hostYou want managed coverage

When AmneziaVPN wins

You want open-source clients, protocol choice including AmneziaWG, and traffic that terminates on a host you rent. Install doors stay on Releases and winget.

When commercial apps win

You want a managed fleet, app-store convenience, and someone else on-call for outages. You accept a monthly seat and less visibility into server operations.

Related

Switch guide: switch. Longer essay: vpn vs commercial. Home: home.

Keep one installer door forever. Mixing Softonic wrappers with Releases and winget on the same PC creates duplicate installs and confused uninstalls. After every reimage, prove one short tunnel before you call the machine ready.

Mist Latch maps filenames and package ids for people who searched for a self-hosted client and need a local AmneziaVPN path. Upstream remains at amnezia.org and amnezia-vpn/amnezia-client under GPL-3.0. VPS billing stays your responsibility and stays separate from the program licence.

When Releases add or drop OS assets on a tag, re-check the live list before you image a classroom. Prefer Windows-bearing tags for the x64 exe. Prefer winget when that index matches machine policy. Refuse review portals that only rank with a renamed setup.

  • Match AmneziaVPN_*_windows_x64.exe on Windows when Releases is the door.
  • Use winget install -e --id AmneziaVPN.AmneziaVPN when winget is allowed.
  • Use the macOS pkg or Linux .run from the same honest tag.
  • Keep commercial apps as a brief fallback while you prove the tunnel.
  • Return to the same door for updates instead of inventing a mirror.

Family PCs, student laptops, and shared desks all benefit from the same rhythm: one installer door, one server record, one documented protocol. That is how the habit stays boring in a good way.

When someone pastes a random download link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.

Keep one installer door forever. Mixing Softonic wrappers with Releases and winget on the same PC creates duplicate installs and confused uninstalls. After every reimage, prove one short tunnel before you call the machine ready.

Mist Latch maps filenames and package ids for people who searched for a self-hosted client and need a local AmneziaVPN path. Upstream remains at amnezia.org and amnezia-vpn/amnezia-client under GPL-3.0. VPS billing stays your responsibility and stays separate from the program licence.

When Releases add or drop OS assets on a tag, re-check the live list before you image a classroom. Prefer Windows-bearing tags for the x64 exe. Prefer winget when that index matches machine policy. Refuse review portals that only rank with a renamed setup.

  • Match AmneziaVPN_*_windows_x64.exe on Windows when Releases is the door.
  • Use winget install -e --id AmneziaVPN.AmneziaVPN when winget is allowed.
  • Use the macOS pkg or Linux .run from the same honest tag.
  • Keep commercial apps as a brief fallback while you prove the tunnel.
  • Return to the same door for updates instead of inventing a mirror.

Family PCs, student laptops, and shared desks all benefit from the same rhythm: one installer door, one server record, one documented protocol. That is how the habit stays boring in a good way.

When someone pastes a random download link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.

Keep one installer door forever. Mixing Softonic wrappers with Releases and winget on the same PC creates duplicate installs and confused uninstalls. After every reimage, prove one short tunnel before you call the machine ready.

Mist Latch maps filenames and package ids for people who searched for a self-hosted client and need a local AmneziaVPN path. Upstream remains at amnezia.org and amnezia-vpn/amnezia-client under GPL-3.0. VPS billing stays your responsibility and stays separate from the program licence.

When Releases add or drop OS assets on a tag, re-check the live list before you image a classroom. Prefer Windows-bearing tags for the x64 exe. Prefer winget when that index matches machine policy. Refuse review portals that only rank with a renamed setup.

  • Match AmneziaVPN_*_windows_x64.exe on Windows when Releases is the door.
  • Use winget install -e --id AmneziaVPN.AmneziaVPN when winget is allowed.
  • Use the macOS pkg or Linux .run from the same honest tag.
  • Keep commercial apps as a brief fallback while you prove the tunnel.
  • Return to the same door for updates instead of inventing a mirror.

Family PCs, student laptops, and shared desks all benefit from the same rhythm: one installer door, one server record, one documented protocol. That is how the habit stays boring in a good way.

When someone pastes a random download link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.