███╗   ███╗ ██████╗  █████╗ ██╗   ██╗
 ████╗ ████║██╔═══██╗██╔══██╗██║   ██║
 ██╔████╔██║██║   ██║███████║██║   ██║
 ██║╚██╔╝██║██║   ██║██╔══██║╚██╗ ██╔╝
 ██║ ╚═╝ ██║╚██████╔╝██║  ██║ ╚████╔╝
 ╚═╝     ╚═╝ ╚═════╝ ╚═╝  ╚═╝  ╚═══╝

Mother of all VPNs

Multi-protocol Internet censorship circumvention stack
optimized for hostile network environments

Quick Install
$ curl -fsSL moav.sh/install.sh | bash

Why MoaV?

Internet access is a human right. MoaV exists because censorship shouldn't.

When a government throttles or shuts down the internet, people lose access to their basic digital rights and cannot reach their families. MoaV turns a single server into a censorship-resistant gateway that runs 16+ circumvention protocols at once, so the moment one is blocked, traffic fails over to another.
Run it for yourself, share access with people you trust, or donate spare bandwidth to networks that reach millions living under shutdowns.

See It In Action

From zero to all protocols running in minutes

01

Quick Installation

Demo coming soon

Click to enlarge
02

Setup & Bootstrap

Demo coming soon

Click to enlarge
03

Admin & User Management

Web-based admin panel

Prometheus stats, user management, config bundles, MahsaNet donations

Click to enlarge
05

Service Management

Demo coming soon

Click to enlarge
06

Grafana Monitoring

Real-time metrics

Per-user traffic, protocol breakdown, country distribution

Click to enlarge
08

User Config Bundles

Config bundles with QR codes

Zip, share, scan, connect

Click to enlarge

Architecture Overview

                                                              ┌───────────────┐  ┌───────────────┐
       ┌───────────────┐                                      │ Psiphon Users │  │   Tor Users   │
       │    Clients    │                                      │  (worldwide)  │  │  (worldwide)  │
       │   (private)   │                                      └───────┬───────┘  └───────┬───────┘
       └───────┬───────┘                                              │                  │
               │                                                      │                  │
               ├─────────────────┐                                    │                  │
               │                 │ Route through CDN                  │                  │
               │          ┌──────┴───────┐                            │                  │
               │          │ Cloudflare / │                            │                  │
               │          │AWS CloudFront│                            │                  │
               │          └──────┬───────┘                            │                  │
               │                 │                                    │                  │
┌──────────────╪─────────────────╪────────────────────────────────────╪──────────────────╪─────────┐
              │                 │          Restricted Internet       │                  │         
└──────────────╪─────────────────╪────────────────────────────────────╪──────────────────╪─────────┘
               │                 │                                    │                  │
╔══════════════════════════════════════════ MoaV Server ═══════════════════════════════════════╗
              │                 │                                    │                  │         
     ┌────────┼─────────────────┼───────┼──────┐                     │                  │         
     │        │         │       │       │      │                     │                  │         
     ▼        ▼         ▼       ▼       ▼      ▼                     ▼                  ▼         
 ┌─────────┐┌─────────┐┌───────┐┌─────────┐┌────────┐          ┌───────────┐      ┌───────────┐   
Reality ││WireGuard││ Trust ││  DNS    ││Telegram│          │           │      │           │   
 │ 443/tcp ││51820/udp││Tunnel ││ 53/udp  ││MTProxy │          │  Conduit  │      │ Snowflake
Trojan  ││AmneziaWG││4443/  │├─────────┤│993/tcp │          │  (donate  │      │  (donate  │   
 │8443/tcp ││51821/udp││tcp+udp││  dnstt  │└───┬────┘          │ bandwidth)│      │ bandwidth)│   
Hysteria2││wstunnel ││       ││Slipstrm │    │               └─────┬─────┘      └─────┬─────┘   
 │ 443/udp ││8080/tcp ││       │└────┬────┘    │                     │                  │         
CDN WS  │└────┬────┘└───┬───┘     │         │                     │                  │         
 │2082/tcp │     │         │         │         │  ┌────────────────┐ │                  │         
 ├─────────┤     │         │         │         │  │ Grafana  :9444 │ │                  │         
sing-box│     │         │         │         │  │ Prometheus     │ │                  │         
 └────┬────┘     │         │         │         │  └────────────────┘ │                  │         
      │          │         │         │         │                     │                  │         
╚═══════════════════════════════════════════════════════════════════════════════════════════╝
       │          │         │         │         │                     │                  │
       ▼          ▼         ▼         ▼         ▼                     ▼                  ▼
┌─────────────────────────────────────────────────────────────────────────────────────────────────┐
                                        Open Internet                                            
└─────────────────────────────────────────────────────────────────────────────────────────────────┘
                    

Quick Start

From zero to running in minutes. Use the one-liner setup.

Or let an AI agent do it Set up MoaV on my Linux server, moav.sh/llms.txt
1

Install with One Command

Terminal
curl -fsSL moav.sh/install.sh | bash

Installs requirements, clones MoaV, prompts for domain/email/password, and starts the interactive setup.

Manual install (alternative)
Terminal
git clone https://github.com/MotherofallVPNs/moav.git
cd moav
./moav.sh
2

Use the CLI

Terminal
moav                   # Interactive menu
moav status            # Service status & health
moav doctor            # Diagnose common issues
moav help              # All commands

After installation, use moav from anywhere. Run moav help for all commands.

3

Download Configs & Connect

Download user bundles from the admin dashboard at https://your-server:9443. Each bundle includes a readme.html with client setup instructions for every protocol.

Prefer an always-on local proxy with a dashboard, load-balancing, and automatic failover? Run the self-hosted MoaV Client.

Multi-Protocol Arsenal

Multiple protocols, one stack. If one is blocked, others take over.

Protocol
What it does
Ports / transport
Stealth & proxy
The universal proxy platform. Reality (VLESS), Trojan, AnyTLS, Hysteria2 and Shadowsocks-2022 in one engine. Traffic mimics real TLS or QUIC; CDN mode routes traffic through Cloudflare or AWS CloudFront.
443/tcp443/udp8443/tcp8445/tcp8388/tcp+udpCDN
Penetrates Everything. VLESS over the XHTTP transport with Reality TLS camouflage, and more.
2096/tcpXray-core
Fake-TLS V2 proxy for direct Telegram access when it is blocked. Emulates real TLS on the IMAPS port, with 17+ anti-DPI tuning knobs and no domain needed.
993/tcp
Full VPN
Fast kernel-level WireGuard. Direct UDP, or tunneled over WebSocket (wss/TLS) with wstunnel when UDP is blocked.
51820/udp8080/tcp
Obfuscated WireGuard that defeats DPI with junk packets, randomized handshake timing and modified headers. Same speed, no fingerprint.
51821/udp
Full tunnel over HTTP/2 and HTTP/3 (QUIC). Carries all traffic while looking exactly like normal HTTPS to deep packet inspection.
4443/tcp+udp
Last-resort tunnels
Four tunnels (dnstt, Slipstream, MasterDNS, XDNS) share port 53 via dns-router, routed by subdomain. Slow but resilient, they keep messaging alive during shutdowns when DNS is all that still resolves.
53/udpdns-router
GooseRelayExperimental
SOCKS5 domain-fronted through a Google Apps Script you deploy, so it looks like traffic to google.com. AES-256-GCM end to end. Survives when the server IP is blocked but Google is reachable.
8444/tcpvia Google
Donate bandwidth to the Psiphon network. Psiphon app users worldwide, including in Iran, are brokered through your server automatically.
Psiphon Network
Run a Snowflake proxy and donate bandwidth to Tor, helping users in censored regions reach the Tor network.
Tor Network
Donate your MoaV configs (Reality, Hysteria2, Trojan, CDN) to the Mahsa VPN, reaching Mahsaserver Network's 12M+ users.
config donation
Your protocol?
Easy to add. Know one that should be here?

Support the Project

Help keep the internet free and open

MoaV Technical Summary

MoaV (Mother of all VPNs) version 2.2.2 is a free, open-source, self-hosted censorship circumvention stack designed for countries with heavy internet censorship such as Iran, China, and Russia. It deploys 16+ anti-censorship protocols in a single Docker Compose command: Reality (VLESS) for TLS camouflage, XHTTP via Xray-core for multiplexed HTTP with Reality camouflage requiring no domain, Trojan for HTTPS mimicry, AnyTLS for defeating TLS-in-TLS fingerprinting, Hysteria2 for QUIC-based fast connections, Shadowsocks-2022 (AEAD-2022 ciphers with active-probing resistance, Outline-compatible), TrustTunnel for HTTP/2 and QUIC tunneling, AmneziaWG for DPI-resistant obfuscated WireGuard, CDN mode routing VLESS through Cloudflare or AWS CloudFront, standard WireGuard with optional WebSocket tunneling, four DNS tunnels — dnstt, Slipstream (QUIC-over-DNS), MasterDNS (ARQ + resolver load-balancing, native to MahsaNG v16), and XDNS (Xray-core FinalMask) — that all run simultaneously on port 53 via the dns-router (fanned out by subdomain) and work during heavy internet shutdowns, Telegram MTProxy with anti-DPI tuning (17 configurable settings), GooseRelay for SOCKS5 tunneled through a user-deployed Google Apps Script fronted as google.com (MahsaNG v16), Psiphon Conduit for bandwidth donation, Tor Snowflake for Tor network support, and MahsaNet config donation to Mahsa VPN (12M+ users worldwide).

Key features include: GeoIP country distribution showing where users connect from on Grafana dashboards (powered by DB-IP Lite, fully offline), web-based admin dashboard on port 9443 with Prometheus-backed aggregate stats across all protocols, Grafana monitoring on port 9444 with per-user traffic metrics and geographic distribution, MahsaNet/MahsaAlert integration to donate VPN configurations to Mahsa VPN (over 12 million users in Iran) using the 'moav donate' command, automatic protocol fallback when individual protocols are blocked, Docker security hardening with cap_drop ALL and read-only filesystems, multi-user credential management with downloadable config bundles and QR codes, moav doctor diagnostics with DNS zone file export, shell autocompletion for bash and zsh, domainless deployment mode for servers without a domain name, and a decoy website with anti-fingerprinting randomization.

Installation: curl -fsSL moav.sh/install | bash. Source code: github.com/MotherofallVPNs/moav. License: MIT. The project has an active open-source community contributing via GitHub issues and pull requests.

Support the project