How to Set Up a VPN on Android: VLESS Reality with Happ (2026)

SetupUpdated September 25, 202610 min read

Android gives VPN apps more to work with than most systems: a proper VPN interface, a system-level kill switch, and the same app on phones and TVs. The import takes a minute. What usually goes wrong comes later, when power management or a network setting ends the tunnel without warning. This guide covers both parts.

The worked example in Step 1 is Kovra, the service that publishes this guide. Every other step applies to any provider that gives you a VLESS subscription link. If you are new to subscription links, what a subscription link is takes three minutes to read.

What you need

  • Android 5.0 or newer. That is Happ's stated minimum. The Always-on VPN switch in Step 5 needs Android 7.0 or newer, and Block connections without VPN needs Android 8.0 or newer.
  • An active plan with a free device slot. Each phone, tablet or TV uses one slot.
  • A link created for this phone. Kovra binds each link to the first device that opens it, so a link already used on another device will not work here.

VPN use is legal in most countries, but some restrict or ban it. Check the rules where you are before you rely on one.

Step 1: get the link for this phone

Sign in to your Kovra dashboard and press Add device (it reads Connect if you have no devices yet), then pick Android. A new card named Android appears with the subscription link, a copy button, a QR code option and a Reset device binding button. The dashboard also offers a Happ download button for the device you just added.

  • Dashboard open on the phone itself: tap the copy button next to the link.
  • Dashboard open on a computer: show the QR code and scan it from the phone in Step 3.
  • Link starts with kovravpn.com/p/: this is a one-tap import page, not a plain subscription address. Open it in the phone's browser, or scan its QR code with the phone's camera, and it hands the subscription to Happ once Happ is installed.

Every device you add uses a slot. The 1-device plan has one, the 3-device plan has three, and an extra slot costs $5 for 30 days on top of any plan. With another provider, copy whatever subscription link it gives you; the import works the same way.

Step 2: install a client

Install Happ - Proxy Utility from Google Play. Its package name is com.happproxy, which you can see in the Play Store web address, and the developer shown on the listing is HappDev. For phones without Google Play, Happ publishes APK files on its official GitHub page (Happ-proxy/happ-android). Use either of those two sources and nothing else.

INCY (listed on Google Play as "incy", by INCY-DEV, package llc.itdev.incy) reads the same subscription link and is a reasonable alternative. Menu names below are Happ's.

Skip APK mirror sites, which can serve modified builds, and the Play Store's "top free VPN" chart, for the reasons in are free VPNs safe.

Step 3: import the subscription

  1. Open Happ.
  2. Tap the + button and choose to paste from the clipboard, or choose the QR code option and point the camera at the code on your computer screen. Labels differ slightly between Happ versions.
  3. The subscription appears with one entry per location. Kovra's subscription asks Happ to refresh it every hour, so added or replaced locations arrive without re-importing anything. To refresh by hand, use the menu next to the subscription.

If Happ shows "Timeout while adding a subscription", the subscription server did not answer within nine seconds, which is Happ's documented limit. Try again, or switch between Wi-Fi and mobile data. The network you are on may be slow or filtering the request.

Step 4: accept Android's VPN request

Pick a location and tap the connect button. The first time, Android shows a system dialog asking whether Happ may set up a VPN connection. Tap OK. When the tunnel is up, a key icon appears in the status bar.

Android runs only one VPN app at a time, so connecting Happ disconnects any other VPN app. If another app is set to Always-on VPN, switch that off first, or the two will fight over the tunnel.

Step 5: Always-on VPN and Block connections without VPN

These are Android system settings, not app features, so they work the same with any client:

  • Always-on VPN starts the VPN when the phone boots and restarts it if it stops.
  • Block connections without VPN drops all traffic while the tunnel is down. This is Android's own kill switch.

On Pixel and phones with stock Android, open Settings, Network & internet, VPN, and tap the gear icon next to Happ. On Samsung, the VPN screen is under Settings, Connections, More connection settings, VPN. Other manufacturers move it around, so search Settings for "VPN". Turn on both switches. If they are greyed out, the app has opted out of Android's Always-on mode, which Android allows VPN apps to do.

The trade-off: with blocking on, hotel, airport and train Wi-Fi login pages cannot load, because the phone cannot reach the login page until the VPN is up, and the VPN cannot come up until you have logged in. Turn blocking off, log in, then turn it back on. The same applies if your plan ends or the link stops working: with blocking on, the phone cannot reach anything, including your dashboard, until you switch blocking off. The full routine is in VPN not working on hotel Wi-Fi.

Step 6: three settings that quietly kill the tunnel

Battery optimisation and background limits

Android stops background apps to save power, and some manufacturers do it much harder than others. When the VPN app is stopped, the tunnel goes with it. Without blocking, traffic silently falls back to your normal connection. With blocking on, the phone simply has no internet. Exempt the app:

  • Pixel and stock Android: Settings, Apps, Happ, App battery usage, Unrestricted.
  • Samsung: the same path ends at Battery, Unrestricted. Also check that Happ is not in the sleeping or deep sleeping apps lists under Settings, Battery, Background usage limits.
  • Xiaomi, OPPO, vivo, Huawei and others: look for autostart and battery saver settings on the app's info page. The names change with every system version, and the site dontkillmyapp.com keeps per-brand instructions.

Private DNS set to a custom hostname

Android's Private DNS setting has three positions: Off, Automatic, and a specific provider hostname. On Pixel it is under Settings, Network & internet, Private DNS. On Samsung it is under Settings, Connections, More connection settings, Private DNS. A custom hostname makes Android insist on that DNS-over-TLS server. If it cannot be reached through the tunnel, apps cannot look up names: the key icon is on and nothing loads. Set it to Automatic while you test. The wider checklist is in VPN connected but no internet.

Data Saver

With Data Saver on, apps in the background cannot use mobile data unless they are on the unrestricted list. On some phones a VPN app counts as a background app, and the result is a tunnel that works on Wi-Fi and stalls on mobile data. On Pixel, open Settings, Network & internet, Data Saver, Unrestricted data, and switch Happ on. On Samsung, open Settings, Connections, Data usage, Data saver, and allow Happ to use data while Data saver is on. While you are there, check that the app's own Background data switch is on.

Optional: keep some apps outside the tunnel

Happ for Android has a Per App Proxy feature: pick the apps that use the tunnel, or invert the list to exclude them instead. It sits in Happ's settings, and its exact place has moved between versions. Typical uses are a banking app that rejects foreign connections or a local delivery or taxi app.

Two things to know. An excluded app uses your normal connection and gets none of the tunnel's protection. And some apps check whether any VPN is active on the phone, and they complain whether or not you exclude them. Happ's release notes also say that private network addresses are excluded by default. Printers and casting targets on your home network therefore stay reachable with the VPN on.

Android TV and Google TV

Happ's Android TV app is the same app, installed from the same Google Play listing. In the Kovra dashboard, add a device of the TV type, which means Android TV and Google TV. It gets its own link, separate from your phone's.

Typing a long link with a remote is miserable, and a TV has no camera to scan a code. Happ solves this the other way round: the TV shows a QR code, and your phone sends the subscription to it. Happ documents two user-facing ways to do this:

  • Web Import (recommended with Kovra). Choose Web Import on the TV. On your phone, scan the TV's QR code with the camera, or open tv.happ.su and enter the code the TV shows. Paste the TV's link from your dashboard and send it. Your phone's Happ never opens the link, so the binding goes to the TV. The link does pass through Happ's web service on its way. If the TV still shows "One device per link", press Reset device binding on the TV card and refresh the subscription on the TV.
  • Local transfer from Happ on your phone. This sends a subscription that is already in your phone's Happ. If you send your phone's own subscription, the TV receives a link that is bound to the phone and shows "One device per link". To use this route anyway, add the TV's link to your phone, send it, delete it from the phone, press Reset device binding on the TV card, then refresh the subscription on the TV.

Samsung (Tizen) and LG (webOS) TVs cannot run Android apps, so this guide does not cover them.

Verify once

With the tunnel up, check three things: that your public IP address belongs to the location you picked, that DNS lookups are not answered by your mobile carrier or home provider, and that IPv6 is not leaking your real address. The VPN leak test walks through each check. If you turned on blocking, also disconnect in Happ and confirm that pages stop loading. That is your kill switch working.

When it fails

Kovra marks problems with entries in the location list whose names end in "kovravpn.com". They point to a dummy local address, so "connecting" to one gives you no internet by design. What each one means is explained in entries that are not servers.

SymptomCauseFix
The only entry is "One device per link - kovravpn.com"The link is bound to another device, or to another VPN app on this phonePress Reset device binding on that link's card, then refresh the subscription on this phone. Or use a separate link for each device
The only entry is "No active plan - kovravpn.com"The plan has endedRenew in the dashboard; the list returns on the next refresh
"Subscription removed - kovravpn.com"The device was deleted in the dashboardAdd a new device and import its link
Connected, key icon on, nothing loadsPrivate DNS hostname, a location unreachable from this network, or a placeholder entry selectedPick another location, set Private DNS to Automatic, then see connected but no internet
Works on Wi-Fi, not on mobile dataData Saver or background data restriction, or the mobile network filters the connectionGive Happ unrestricted data, then try another location on the same network
Drops when the screen is offBattery optimisation stops the appSet battery usage to Unrestricted and remove sleep limits
Wi-Fi login page never appearsBlock connections without VPN is onTurn blocking off, log in, turn it back on

On an iPhone the flow is similar but the system settings are different: see how to set up a VPN on iPhone.

Frequently asked questions

Can I use my phone's VPN link on my tablet too?

Not on Kovra. Each subscription link is bound to the first device that opens it, and any other device receives a single 'One device per link' entry instead of locations. Add a second device in the dashboard for the tablet. The 3-device plan includes three slots, and an extra slot on any plan costs $5 for 30 days.

Does Always-on VPN drain the battery?

The setting itself only tells Android to start the VPN at boot and restart it if it stops. The battery cost comes from keeping the tunnel connected all day, which is the point of the setting. If you already leave the VPN on, Always-on adds little beyond making the restarts automatic.

Do I need to root my phone to use a VPN on Android?

No. Android has a built-in VPN interface for apps, called VpnService, which is what Happ, INCY and every other VPN app use. Root is not needed for the tunnel, Always-on VPN, or per-app routing.

Can I use INCY instead of Happ on Android?

Yes. INCY is on Google Play and reads the same subscription link. Kovra's dashboard buttons and support instructions are written for Happ, so expect menu names in this guide to differ in INCY. If you switch apps on the same phone and see 'One device per link', press Reset device binding in the dashboard and refresh the subscription in the new app.

Why does my banking app complain when the VPN is on?

Two common reasons. The bank's fraud checks may dislike a connection that exits in another country, or the app may refuse to run while any VPN is active on the phone. Excluding the app with per-app routing usually helps in the first case. For the second, pause the VPN while you use the app. An excluded app uses your normal connection and is not protected by the tunnel.

To the network, it's just a website

Kovra runs on VLESS + Reality, takes USDT, BTC and cards, and never asks for a phone number. Plans from $2.75 per month on the annual term, paid once; nothing renews automatically.

Popular searches