What Is a VPN Subscription Link? How It Works, How to Guard It

SetupUpdated September 25, 20269 min read

If a VPN provider gave you a long URL instead of an installer or a username and password, that URL is a subscription link. It is how most VLESS, Xray and sing-box based services, Kovra included, hand configuration to your app. This page explains what the link contains, why it keeps itself up to date, why it deserves the same care as a password, and how Kovra's one-link-per-device rule works in practice.

What a subscription link is

A subscription link is a private HTTPS address. Your VPN app downloads it, reads the list of connection profiles inside, and shows each one as a location you can tap. Later the app goes back to the same address on its own and checks for changes. On some Kovra accounts the dashboard shows a one-tap link instead, starting with kovravpn.com/p/, which opens Happ and imports the subscription for you. It carries the same token and deserves the same care.

Two properties matter more than any technical detail. First, the link needs no login: the server recognises you by the token in the URL alone. Second, because it carries that account token, the response contains working credentials for your plan. That is why the rest of this guide keeps returning to one rule: treat the link like a password.

What your app downloads

Open a subscription link in a browser and you will usually see a block of seemingly random letters. That block is base64, a plain text encoding rather than encryption. Decoded, it is a list with one connection profile per line. Some providers send full JSON configurations instead, but the idea is the same. One VLESS entry, with every private value replaced by a placeholder, looks like this (wrapped for reading; in the real list it is a single line):

vless://<account-id>
  @<server-host>:<port>
  /?type=tcp&encryption=none
  &security=reality
  &flow=xtls-rprx-vision
  &sni=<cover-site>
  &fp=<fingerprint>
  &pbk=<public-key>
  &sid=<short-id>
  #Germany

Each part has a job:

PartWhat it does
vless://The protocol. VLESS is a lightweight transport; the details are in how VLESS and REALITY work.
<account-id>Your credential on the server. This is the part that makes the entry yours.
<server-host>:<port>Where the app connects.
security=reality, sni, pbk, sid, fpREALITY settings: the cover site the connection presents, the server's public key, a short ID and the browser fingerprint to imitate. The name, key and short ID must match the server's settings; the provider picks the fingerprint.
flow=xtls-rprx-visionThe Vision flow, which Kovra uses on every location.
#GermanyThe label your app shows as the location name.

Alongside the list, the server can send refresh hints in the response headers, which apps such as Happ read: how often to re-check the link, when the plan expires, a title for the subscription and a support contact. Kovra uses them to ask for an hourly refresh and to point the app's support button at its Telegram bot.

You may also meet bare vless:// links, shared one at a time. Each describes exactly one server, frozen at the moment the link was made. A subscription link is a pointer to a list that the provider maintains.

FeatureSingle vless:// linkSubscription link
ContainsOne server's settingsAn address that returns a list of servers
A server address changesThe link stops working; you need a new oneThe provider updates the list; the app picks it up
New locationsPasted in by hand, one by oneAppear after the next refresh
Plan status and noticesNot shownCan carry the expiry date and messages

That is why providers prefer subscriptions. Servers move, addresses get blocked or replaced, and a list that updates itself saves everyone from re-sending links. Kovra's dashboard gives you a subscription link for each device.

How updates arrive

Apps re-fetch the link on a timer. Kovra's subscription asks for a refresh every hour, and Happ schedules its automatic updates by that hint, though the phone or computer decides exactly when they run. Every client also has a manual refresh, usually a circular-arrow icon next to the subscription's name; where exactly it sits differs between apps and versions.

  • New or replaced locations appear after the next refresh. You never need to paste the link again for that.
  • The link itself stays the same when the server list changes. The same URL keeps working for as long as the device exists in your dashboard.
  • A refresh also carries your plan status. When a plan runs out, the next refresh replaces the locations with a notice (explained below); after you renew, the next refresh brings them back.

If a refresh fails, apps normally keep the entries they already have. A failed refresh usually means the subscription server could not be reached from your current network, not that anything changed on your account. The connected-but-no-internet checklist covers that case.

Why the link is a secret

Nothing stands between the link and the server list: no password, no second factor. Anyone who has the URL can import it into their own app. In practice:

  • Don't post it in group chats, public forums, issue trackers or social media, including "can someone check my config?" threads.
  • Crop it out of screenshots. The dashboard shows the link on each device card, and many apps show it in their subscription settings.
  • A QR code is the same secret in another shape. A photo of your screen with the code visible hands over the link.
  • Move it between your own devices privately, for example through a personal note or an end-to-end encrypted chat with yourself.
  • Support does not need it to find you. They can find your account from your Telegram or email. Share the link only inside the private support chat, and only if you are asked for it.

One link, one device

Kovra issues a separate link for every device, and each link works on exactly one device. When Happ opens a subscription, it sends a device identifier. The first device that opens a Kovra link is bound to it for a year. Any other device that opens the same link gets a single entry instead of servers:

One device per link - kovravpn.com
One link works on one device. Use a separate link from your dashboard for each device.

The binding exists to keep one link on one device. It is not a substitute for keeping the link private, so the rules in the previous section still apply.

Adding a link for another device

  1. Open your dashboard and press Add device (it reads Connect if you have no devices yet).
  2. Pick the device type: Android, iPhone, Mac, Windows or TV (Android TV and Google TV). The dashboard then links to the matching Happ download.
  3. Copy the new link, or show its QR code and scan it, and import it into the app on that device.

Each device needs a free slot. The 1-device plan includes one slot and the 3-device plan three; an extra slot costs $5 for 30 days, independent of your plan, up to 100 devices per account. If the dashboard says "No free device slot", that is the reason.

Moving a link to a new phone

Each device card in the dashboard has a Reset device binding button. It clears the binding, and the dashboard confirms: "Binding reset. Refresh the subscription on the device you want to use." The next device that opens the link claims it, so the order matters:

  1. Remove the subscription from the old device first, so its automatic refresh cannot claim the link back.
  2. Press Reset device binding on that device's card and confirm.
  3. Straight away, import the link on the new device, or refresh it if it is already there.

Entries that are not servers

Sometimes the list holds a single entry whose name is a sentence rather than a country. These are notices, delivered through the one channel every VPN app understands: a server entry. They point nowhere on purpose, so "connecting" to one gives you no internet. That is by design, not a fault.

Entry nameWhat it means
No active plan - kovravpn.comThe account has no active plan. Happ also shows "No active plan. Buy a plan to keep using Kovra."
Fix: buy or renew a plan, then refresh the subscription.
One device per link - kovravpn.comThis link is bound to another device.
Fix: use this device's own link, or reset the binding as described above.
Subscription removed - kovravpn.comThe device was deleted in the dashboard, so its link is retired.
Fix: add the device again and import the new link.

If you think your link leaked

One warning sign is your own device suddenly showing One device per link when you did not switch devices. The app's device identifier may have changed (a factory reset or reinstall can do that), or the binding was reset and another device refreshed first. Either way:

  1. Press Reset device binding in the dashboard and refresh the subscription on your device immediately, so that your device claims the link first.
  2. If you suspect the link is circulating, delete that device in the dashboard and add it again. The old link then returns Subscription removed, and the new device card carries a fresh link.
  3. Tell support at @KovraVPN_bot or [email protected], especially if you did not reset the binding yourself.

Which apps can read the link

Any app that imports VLESS subscriptions with REALITY can read the format. Kovra's instructions are written for Happ, which is available for iOS, Android, Windows and macOS; INCY also reads Kovra's standard subscription link, while the one-tap kovravpn.com/p/ link is made for Happ. The step-by-step setup is in the guides for Android, iPhone, Windows and Mac.

Two cautions. App availability changes, and some VLESS clients have disappeared from the App Store, so check the current listing before relying on an alternative. And an app that ignores the refresh hints still connects, but it may not show new locations or plan notices until it refreshes on its own schedule or you refresh by hand.

The rules in one place

  • One link per device; create a new link for each device.
  • Treat the link, and its QR code, like a password.
  • Let the app refresh on its own, and refresh by hand after renewing or when something looks wrong.
  • A location named like a sentence is a notice, not a server.
  • Changing phones: remove the subscription from the old one, reset the binding, then refresh on the new one right away.

Frequently asked questions

Is the subscription link the same as my account?

No. Your account is what you sign in to on kovravpn.com, with email or Telegram. The subscription link is a per-device key that the account issues. Someone holding the link does not get into your dashboard, and from the dashboard you can view the link, reset its device binding, or delete the device and create a new link.

Can I share my subscription link with family?

Not on Kovra. A link works on one device only, so a second phone receives a 'One device per link' notice instead of servers. Give each device its own link: add a device slot for $5 per 30 days, or choose the 3-device plan, then create a link for each device in the dashboard.

Does a subscription link expire?

The link keeps working for as long as the device exists in your dashboard. What expires is the plan: without one, the link returns a 'No active plan' entry instead of locations, and after you renew, the next refresh brings the locations back. Deleting the device retires its link for good.

Is a QR code safer than copying the link?

No. The QR code encodes the same URL, so a photo of it is as good as the text. It is simply more convenient for a TV or a second screen. Keep it out of screenshots and shared photos exactly as you would the link.

Why does my only phone say 'One device per link'?

The link is bound to a different device identifier. That can happen when a factory reset or reinstall changed the app's device identifier, when the link was opened on another device first, or after the binding was reset and another device refreshed sooner. Press Reset device binding in the dashboard, then refresh the subscription on your phone straight away.

Which apps can read a Kovra subscription link?

Apps that import VLESS subscriptions with REALITY. Kovra recommends Happ on iOS, Android, Windows and macOS, and INCY also reads the standard link; the one-tap kovravpn.com/p/ link that some accounts get is made for Happ. Check the current app store listing before relying on any alternative, because client availability changes.

To the network, it's just a website

Kovra runs on VLESS + Reality, takes USDT, BTC and cards, and never asks for a phone number. Plans from $2.75 per month on the annual term, paid once; nothing renews automatically.

Popular searches