Android gives VPN apps more to work with than most systems: a proper VPN interface, a system-level kill switch, and the same app on phones and TVs. The import takes a minute. What usually goes wrong comes later, when power management or a network setting ends the tunnel without warning. This guide covers both parts.
The worked example in Step 1 is Kovra, the service that publishes this guide. Every other step applies to any provider that gives you a VLESS subscription link. If you are new to subscription links, what a subscription link is takes three minutes to read.
What you need
- Android 5.0 or newer. That is Happ's stated minimum. The Always-on VPN switch in Step 5 needs Android 7.0 or newer, and Block connections without VPN needs Android 8.0 or newer.
- An active plan with a free device slot. Each phone, tablet or TV uses one slot.
- A link created for this phone. Kovra binds each link to the first device that opens it, so a link already used on another device will not work here.
VPN use is legal in most countries, but some restrict or ban it. Check the rules where you are before you rely on one.
Step 1: get the link for this phone
Sign in to your Kovra dashboard and press Add device (it reads Connect if you have no devices yet), then pick Android. A new card named Android appears with the subscription link, a copy button, a QR code option and a Reset device binding button. The dashboard also offers a Happ download button for the device you just added.
- Dashboard open on the phone itself: tap the copy button next to the link.
- Dashboard open on a computer: show the QR code and scan it from the phone in Step 3.
- Link starts with kovravpn.com/p/: this is a one-tap import page, not a plain subscription address. Open it in the phone's browser, or scan its QR code with the phone's camera, and it hands the subscription to Happ once Happ is installed.
Every device you add uses a slot. The 1-device plan has one, the 3-device plan has three, and an extra slot costs $5 for 30 days on top of any plan. With another provider, copy whatever subscription link it gives you; the import works the same way.
Step 2: install a client
Install Happ - Proxy Utility from Google Play. Its package name is com.happproxy, which you can see in the Play Store web address, and the developer shown on the listing is HappDev. For phones without Google Play, Happ publishes APK files on its official GitHub page (Happ-proxy/happ-android). Use either of those two sources and nothing else.
INCY (listed on Google Play as "incy", by INCY-DEV, package llc.itdev.incy) reads the same subscription link and is a reasonable alternative. Menu names below are Happ's.
Skip APK mirror sites, which can serve modified builds, and the Play Store's "top free VPN" chart, for the reasons in are free VPNs safe.
Step 3: import the subscription
- Open Happ.
- Tap the + button and choose to paste from the clipboard, or choose the QR code option and point the camera at the code on your computer screen. Labels differ slightly between Happ versions.
- The subscription appears with one entry per location. Kovra's subscription asks Happ to refresh it every hour, so added or replaced locations arrive without re-importing anything. To refresh by hand, use the menu next to the subscription.
If Happ shows "Timeout while adding a subscription", the subscription server did not answer within nine seconds, which is Happ's documented limit. Try again, or switch between Wi-Fi and mobile data. The network you are on may be slow or filtering the request.
Step 4: accept Android's VPN request
Pick a location and tap the connect button. The first time, Android shows a system dialog asking whether Happ may set up a VPN connection. Tap OK. When the tunnel is up, a key icon appears in the status bar.
Android runs only one VPN app at a time, so connecting Happ disconnects any other VPN app. If another app is set to Always-on VPN, switch that off first, or the two will fight over the tunnel.
Step 5: Always-on VPN and Block connections without VPN
These are Android system settings, not app features, so they work the same with any client:
- Always-on VPN starts the VPN when the phone boots and restarts it if it stops.
- Block connections without VPN drops all traffic while the tunnel is down. This is Android's own kill switch.
On Pixel and phones with stock Android, open Settings, Network & internet, VPN, and tap the gear icon next to Happ. On Samsung, the VPN screen is under Settings, Connections, More connection settings, VPN. Other manufacturers move it around, so search Settings for "VPN". Turn on both switches. If they are greyed out, the app has opted out of Android's Always-on mode, which Android allows VPN apps to do.
Step 6: three settings that quietly kill the tunnel
Battery optimisation and background limits
Android stops background apps to save power, and some manufacturers do it much harder than others. When the VPN app is stopped, the tunnel goes with it. Without blocking, traffic silently falls back to your normal connection. With blocking on, the phone simply has no internet. Exempt the app:
- Pixel and stock Android: Settings, Apps, Happ, App battery usage, Unrestricted.
- Samsung: the same path ends at Battery, Unrestricted. Also check that Happ is not in the sleeping or deep sleeping apps lists under Settings, Battery, Background usage limits.
- Xiaomi, OPPO, vivo, Huawei and others: look for autostart and battery saver settings on the app's info page. The names change with every system version, and the site dontkillmyapp.com keeps per-brand instructions.
Private DNS set to a custom hostname
Android's Private DNS setting has three positions: Off, Automatic, and a specific provider hostname. On Pixel it is under Settings, Network & internet, Private DNS. On Samsung it is under Settings, Connections, More connection settings, Private DNS. A custom hostname makes Android insist on that DNS-over-TLS server. If it cannot be reached through the tunnel, apps cannot look up names: the key icon is on and nothing loads. Set it to Automatic while you test. The wider checklist is in VPN connected but no internet.
Data Saver
With Data Saver on, apps in the background cannot use mobile data unless they are on the unrestricted list. On some phones a VPN app counts as a background app, and the result is a tunnel that works on Wi-Fi and stalls on mobile data. On Pixel, open Settings, Network & internet, Data Saver, Unrestricted data, and switch Happ on. On Samsung, open Settings, Connections, Data usage, Data saver, and allow Happ to use data while Data saver is on. While you are there, check that the app's own Background data switch is on.
Optional: keep some apps outside the tunnel
Happ for Android has a Per App Proxy feature: pick the apps that use the tunnel, or invert the list to exclude them instead. It sits in Happ's settings, and its exact place has moved between versions. Typical uses are a banking app that rejects foreign connections or a local delivery or taxi app.
Two things to know. An excluded app uses your normal connection and gets none of the tunnel's protection. And some apps check whether any VPN is active on the phone, and they complain whether or not you exclude them. Happ's release notes also say that private network addresses are excluded by default. Printers and casting targets on your home network therefore stay reachable with the VPN on.
Android TV and Google TV
Happ's Android TV app is the same app, installed from the same Google Play listing. In the Kovra dashboard, add a device of the TV type, which means Android TV and Google TV. It gets its own link, separate from your phone's.
Typing a long link with a remote is miserable, and a TV has no camera to scan a code. Happ solves this the other way round: the TV shows a QR code, and your phone sends the subscription to it. Happ documents two user-facing ways to do this:
- Web Import (recommended with Kovra). Choose Web Import on the TV. On your phone, scan the TV's QR code with the camera, or open tv.happ.su and enter the code the TV shows. Paste the TV's link from your dashboard and send it. Your phone's Happ never opens the link, so the binding goes to the TV. The link does pass through Happ's web service on its way. If the TV still shows "One device per link", press Reset device binding on the TV card and refresh the subscription on the TV.
- Local transfer from Happ on your phone. This sends a subscription that is already in your phone's Happ. If you send your phone's own subscription, the TV receives a link that is bound to the phone and shows "One device per link". To use this route anyway, add the TV's link to your phone, send it, delete it from the phone, press Reset device binding on the TV card, then refresh the subscription on the TV.
Samsung (Tizen) and LG (webOS) TVs cannot run Android apps, so this guide does not cover them.
Verify once
With the tunnel up, check three things: that your public IP address belongs to the location you picked, that DNS lookups are not answered by your mobile carrier or home provider, and that IPv6 is not leaking your real address. The VPN leak test walks through each check. If you turned on blocking, also disconnect in Happ and confirm that pages stop loading. That is your kill switch working.
When it fails
Kovra marks problems with entries in the location list whose names end in "kovravpn.com". They point to a dummy local address, so "connecting" to one gives you no internet by design. What each one means is explained in entries that are not servers.
| Symptom | Cause | Fix |
|---|---|---|
| The only entry is "One device per link - kovravpn.com" | The link is bound to another device, or to another VPN app on this phone | Press Reset device binding on that link's card, then refresh the subscription on this phone. Or use a separate link for each device |
| The only entry is "No active plan - kovravpn.com" | The plan has ended | Renew in the dashboard; the list returns on the next refresh |
| "Subscription removed - kovravpn.com" | The device was deleted in the dashboard | Add a new device and import its link |
| Connected, key icon on, nothing loads | Private DNS hostname, a location unreachable from this network, or a placeholder entry selected | Pick another location, set Private DNS to Automatic, then see connected but no internet |
| Works on Wi-Fi, not on mobile data | Data Saver or background data restriction, or the mobile network filters the connection | Give Happ unrestricted data, then try another location on the same network |
| Drops when the screen is off | Battery optimisation stops the app | Set battery usage to Unrestricted and remove sleep limits |
| Wi-Fi login page never appears | Block connections without VPN is on | Turn blocking off, log in, turn it back on |
On an iPhone the flow is similar but the system settings are different: see how to set up a VPN on iPhone.