VPN: self-hosted client vs commercial apps
By Mist Latch editorial team Current release, published August 21, 2026
A self-hosted vpn client under GPL-3.0 (AmneziaVPN) aims at servers you operate. Commercial subscription apps sell managed fleets. Pick based on whether you want to run the server.
| Factor | AmneziaVPN | Commercial apps |
|---|---|---|
| Price | Free client; you pay for a VPS | Monthly seat |
| Source | GPL-3.0 on GitHub | Usually closed |
| Servers | Yours | Vendor fleet |
| Support | Community + docs | Vendor support desks |
| Best when | You can SSH and maintain a host | You want managed coverage |
When AmneziaVPN wins
You want open-source clients, protocol choice including AmneziaWG, and traffic that terminates on a host you rent. Install doors stay on Releases and winget.
When commercial apps win
You want a managed fleet, app-store convenience, and someone else on-call for outages. You accept a monthly seat and less visibility into server operations.
Related
Switch guide: switch. Longer essay: vpn vs commercial. Home: home.
Keep one installer door forever. Mixing Softonic wrappers with Releases and winget on the same PC creates duplicate installs and confused uninstalls. After every reimage, prove one short tunnel before you call the machine ready.
Mist Latch maps filenames and package ids for people who searched for a self-hosted client and need a local AmneziaVPN path. Upstream remains at amnezia.org and amnezia-vpn/amnezia-client under GPL-3.0. VPS billing stays your responsibility and stays separate from the program licence.
When Releases add or drop OS assets on a tag, re-check the live list before you image a classroom. Prefer Windows-bearing tags for the x64 exe. Prefer winget when that index matches machine policy. Refuse review portals that only rank with a renamed setup.
- Match
AmneziaVPN_*_windows_x64.exeon Windows when Releases is the door. - Use
winget install -e --id AmneziaVPN.AmneziaVPNwhen winget is allowed. - Use the macOS pkg or Linux .run from the same honest tag.
- Keep commercial apps as a brief fallback while you prove the tunnel.
- Return to the same door for updates instead of inventing a mirror.
Family PCs, student laptops, and shared desks all benefit from the same rhythm: one installer door, one server record, one documented protocol. That is how the habit stays boring in a good way.
When someone pastes a random download link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.
Keep one installer door forever. Mixing Softonic wrappers with Releases and winget on the same PC creates duplicate installs and confused uninstalls. After every reimage, prove one short tunnel before you call the machine ready.
Mist Latch maps filenames and package ids for people who searched for a self-hosted client and need a local AmneziaVPN path. Upstream remains at amnezia.org and amnezia-vpn/amnezia-client under GPL-3.0. VPS billing stays your responsibility and stays separate from the program licence.
When Releases add or drop OS assets on a tag, re-check the live list before you image a classroom. Prefer Windows-bearing tags for the x64 exe. Prefer winget when that index matches machine policy. Refuse review portals that only rank with a renamed setup.
- Match
AmneziaVPN_*_windows_x64.exeon Windows when Releases is the door. - Use
winget install -e --id AmneziaVPN.AmneziaVPNwhen winget is allowed. - Use the macOS pkg or Linux .run from the same honest tag.
- Keep commercial apps as a brief fallback while you prove the tunnel.
- Return to the same door for updates instead of inventing a mirror.
Family PCs, student laptops, and shared desks all benefit from the same rhythm: one installer door, one server record, one documented protocol. That is how the habit stays boring in a good way.
When someone pastes a random download link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.
Keep one installer door forever. Mixing Softonic wrappers with Releases and winget on the same PC creates duplicate installs and confused uninstalls. After every reimage, prove one short tunnel before you call the machine ready.
Mist Latch maps filenames and package ids for people who searched for a self-hosted client and need a local AmneziaVPN path. Upstream remains at amnezia.org and amnezia-vpn/amnezia-client under GPL-3.0. VPS billing stays your responsibility and stays separate from the program licence.
When Releases add or drop OS assets on a tag, re-check the live list before you image a classroom. Prefer Windows-bearing tags for the x64 exe. Prefer winget when that index matches machine policy. Refuse review portals that only rank with a renamed setup.
- Match
AmneziaVPN_*_windows_x64.exeon Windows when Releases is the door. - Use
winget install -e --id AmneziaVPN.AmneziaVPNwhen winget is allowed. - Use the macOS pkg or Linux .run from the same honest tag.
- Keep commercial apps as a brief fallback while you prove the tunnel.
- Return to the same door for updates instead of inventing a mirror.
Family PCs, student laptops, and shared desks all benefit from the same rhythm: one installer door, one server record, one documented protocol. That is how the habit stays boring in a good way.
When someone pastes a random download link into chat, ask for the GitHub Releases URL instead. The install path on this guide always returns to amnezia-vpn/amnezia-client.