HomeHyrax
ENDE

Your smart VPN assistant

Your home network as an app.

Smart home, NAS, Shelly, cameras – one tap away. Direct at home, through your own tunnel when away.

  • Free
  • No account with us
  • No ads, no tracking
  • Open source (Apache-2.0)
  • Android 8+
HomeHyrax home screen with camera, website and switch tiles
Away · via WireGuard
Home · direct

The idea

VPN only where you need it

A phone-wide VPN

  • all traffic goes through your home
  • disturbs Android Auto, navigation, banking
  • blocks your other VPN – switched by hand

HomeHyrax

  • tunnel only inside the app, only for your devices
  • everything else stays normal
  • switches on and off by itself

Automatic

The tunnel switches itself

You just tap the icon.

At home on Wi-Filoads directly, no tunnel
Direct
Away or on another Wi-Fimobile data, hotel, campsite, office
Tunnel on
App closed90 s later the tunnel is gone
Tunnel off

Several tunnels at once

Home, camper, office

Every entry knows its tunnel – HomeHyrax picks the right one.

  • WireGuard – e.g. FRITZ!Box, OpenWrt, OPNsense, UniFi
  • Tailscale / Headscale – without a public IP (DS-Lite, LTE)
Your phoneHomeHyrax
HomeFRITZ!Box · WireGuard
CamperLTE router · Tailscale
OfficeWireGuard
Everything elsedirect, no tunnel

Three kinds of entries

Websites, switches, cameras

Camper dashboard opened away via WireGuard
Website

Any web interface as an app

  • Full screen with its own home-screen icon
  • Badge shows Home · direct or Away · via WireGuard
  • Live values stay live, pull down to reload
Switch tile reports: Heating switched on
Switch

One tap – garage door, heating

  • Shelly Gen1–Gen3: pulse, on, off, toggle
  • Shows the real state: Switched on
  • Fingerprint before switching
Live camera view from inside a camper
Camera

Live view via RTSP

  • e.g. Eufy – without the manufacturer's cloud
  • Fresh picture in the tile on every start
Share via QR code Fingerprint lock Own icons Connection test

Setup

Ready in three steps

1

Install

from Google Play – free.

2

Add a tunnel

+ Tunnel → scan the FRITZ!Box QR code or sign in with Tailscale.

3

Add an entry

+ New → address, VPN Smart, done.

Detailed guide

WireGuard or Tailscale?

WireGuard

Fastest and most private
  • Phone connects directly to your router, nobody in between
  • Needs a connection reachable from outside: own public IPv4 (classic DSL/fiber) or IPv6
  • Built into the FRITZ!Box from FRITZ!OS 7.50

Tailscale / Headscale

When the router isn't reachable from outside
  • For DS-Lite, CGNAT, many cable/fiber lines, LTE/5G routers – e.g. in the camper
  • No port forwarding: both sides connect outward
  • Needs a device at home as subnet router (Raspberry Pi, NAS …)
  • Sign-in via Tailscale (free for personal use) or your own Headscale server

Not sure? If your FRITZ!Box shows an IPv4 address under Internet → Online Monitor that does not start with 100.64–100.127, and the overview does not say “DS-Lite”, WireGuard will usually work. Otherwise take Tailscale.

WireGuard with a FRITZ!Box

From FRITZ!OS 7.50. Other routers: see below.

  1. Open http://fritz.box in a browser and log in.
  2. Go to Internet → Permit Access → VPN (WireGuard) → Add connection.
  3. Choose Connect a single device, name it e.g. “HomeHyrax phone”, continue.
  4. Confirm on the FRITZ!Box when asked (button on the box or phone).
  5. A QR code appears – keep the page open.
  6. In HomeHyrax: Tunnels → + Tunnel → Scan QR code. Alternatives: take a screenshot and choose QR code from image (screenshot), load the file via Choose file (.conf), or … or paste configuration.
  7. Save. With Test connection you see right away whether the FRITZ!Box answers (on your home Wi-Fi the test may fail – that's normal).

One connection per phone. Two phones with the same key disturb each other as soon as both are away at the same time. Create a second connection in the FRITZ!Box for the second phone.

  • The FRITZ!Box uses its MyFRITZ! address (…myfritz.net). HomeHyrax resolves it on every connect – a changing IP is no problem.
  • The FRITZ!Box puts 0.0.0.0/0 (everything through the tunnel) into the configuration. HomeHyrax ignores this on purpose: only the addresses of your tiles use the tunnel.
WireGuard with other routers

HomeHyrax reads the standard WireGuard configuration (wg-quick format). Any router or server that creates such a file or QR code for a device (“peer”, “client”) works.

DeviceWhere
OpenWrtPackage luci-proto-wireguard, Network → Interfaces → WireGuard, add peer, “Generate configuration”
OPNsense / pfSenseVPN → WireGuard, create instance + peer, export the client configuration
UniFi gatewaySettings → VPN → VPN Server → WireGuard, add client, download file
Synology Router, ASUS, GL.iNet …VPN server → WireGuard → create client/profile, file or QR code
Linux / Raspberry PiYour own WireGuard server, e.g. with PiVPN (pivpn add, pivpn -qr)

The configuration for the phone looks like this (example values):

[Interface]
PrivateKey = <key of the phone>
Address = 192.168.178.201/24

[Peer]
PublicKey = <key of the router>
AllowedIPs = 192.168.178.0/24        # your home network
Endpoint = myhome.example.net:51820
PersistentKeepalive = 25

AllowedIPs matters: it must contain your home network. HomeHyrax only sends addresses in this range through the tunnel. The UDP port (here 51820) must be reachable from outside – most routers open it themselves when you set up the WireGuard server.

Tailscale

Tailscale runs inside HomeHyrax – you don't need the Tailscale app or a VPN switched on. You need a free account at tailscale.com (or your own Headscale server) and a device that runs permanently at home and can run Tailscale: Raspberry Pi, NAS (Synology, QNAP, Unraid), Linux PC, some routers (GL.iNet, OpenWrt). It becomes the subnet router and forwards the app's requests to the other devices.

a) Set up the subnet router (example network 192.168.178.0/24 – use yours)

Raspberry Pi / Linux

curl -fsSL https://tailscale.com/install.sh | sh
# allow forwarding (once)
echo 'net.ipv4.ip_forward = 1' | sudo tee /etc/sysctl.d/99-tailscale.conf
sudo sysctl -p /etc/sysctl.d/99-tailscale.conf
# sign in and share the home network
sudo tailscale up --advertise-routes=192.168.178.0/24

The last command shows a link – open it and sign in with your Tailscale account.

Synology NAS (DSM 7): Package Center → install Tailscale, open, sign in. Then via SSH: sudo tailscale set --advertise-routes=192.168.178.0/24

Other devices: install Tailscale and enable “Subnet router” / --advertise-routes with your home network.

b) Approve the route

  1. Open login.tailscale.com/admin/machines.
  2. At the subnet router: ⋯ → Edit route settings and tick the route.
  3. Recommended: same device ⋯ → Disable key expiry, so the router doesn't need a new sign-in after a few months.

c) Connect HomeHyrax

  1. Tunnels → + Tunnel → Tailscale. Leave Own server (Headscale) empty for Tailscale.
  2. Tap Connect. The browser opens the Tailscale sign-in – use the same account as for the subnet router, then return to the app.
  3. The card shows Connected and the shared home network. No home network yet? Step b) is missing.

With an auth key (Tailscale admin → Settings → Keys) you can skip the browser sign-in, e.g. for a family phone. When sharing via QR code, HomeHyrax never passes the auth key on.

Camper with an LTE/5G router

Mobile routers are almost never reachable from outside – take Tailscale.

  • Larger Teltonika models (RUTX, RUTM, TRB1/TRB5) offer Tailscale as a package (System → Package Manager, then Services → VPN → Tailscale; see Teltonika wiki “Tailscale Configuration Example”).
  • Small models like the RUT200 don't have enough memory: connect a Raspberry Pi Zero 2 W by Wi-Fi or LAN and set it up as subnet router as above.
  • Give the camper its own address range (e.g. 192.168.50.0/24), different from home – otherwise the same addresses get mixed up.
Add a website
  1. Home → + New → Website.
  2. Name and Home network address: IP or name, optional port – e.g. 192.168.178.1, 192.168.178.20:8123 or https://nas.local:5001.
  3. VPN: Smart and choose the tunnel.
  4. Tap the icon preview to Choose icon (icons + color) or take an Image from phone.
  5. Optional: Require unlock (fingerprint/face/PIN). Under Advanced: Full screen, Keep screen on, Desktop site.
  6. Save or straight Add to home screen.

Long-press a tile and drag it to reorder. Routers and NAS often use a self-signed certificate: HomeHyrax asks once and then remembers exactly this certificate.

VPN per entry: None / Smart / Always
NoneDirect only, no tunnel – for devices you only use at home.
SmartDirect at home, tunnel when away. The recommended choice.
AlwaysAlways through the tunnel, even at home. No fallback to direct.
Add a switch (Shelly)
  1. + New → Switch → device Shelly.
  2. On your home Wi-Fi: Find Shelly on home network – HomeHyrax lists all Shellys with name, generation and whether a password is set. Away or not found: Set up manually with the Shelly IP and generation.
  3. Choose the Channel (0 = first output) and the Action: Pulse – e.g. garage door (briefly on, then off automatically, duration in seconds), Turn on, Turn off or Toggle.
  4. If the Shelly has a password: enter it – it's stored encrypted and only sent when the Shelly asks (Gen1 Basic, Gen2 Digest SHA-256).
  5. VPN Smart, choose the tunnel, save.

Tapping the tile asks for your fingerprint (can be switched off), sends the command and shows the real state: Switched on / Switched off. With a pulse, it checks again afterwards and warns if the relay is still on. Other devices: Custom URL – HomeHyrax calls exactly this address.

Add a camera (RTSP)
  1. In the camera's app, enable the local RTSP stream and copy the link. Eufy: Settings → NAS (RTSP), recording set to “always” – with “on motion” the camera answers “stream not found”.
  2. HomeHyrax: + New → Camera → paste the link under RTSP address. User and password are split off automatically into Camera user / Camera password.
  3. VPN Smart, choose the tunnel, save.

Battery cameras without a base station (e.g. Reolink Argus, many eufyCams) usually offer no local stream. Cloud-only cameras are not supported.

Share with your family
  1. On your phone: ⋮ → Share HomeHyrax, choose entries and tunnels → Show QR code or Send as file (with images).
  2. On the other phone: install HomeHyrax → ⋮ → Import HomeHyrax → scan the code or Open received file.
  3. A preview shows what is new or updated. Existing entries keep their connection and passwords.

The code contains keys for your home network – only let it be scanned directly from the screen. For WireGuard, better create a separate connection for each phone. Tailscale is shared without sign-in, the other phone signs in itself.

How HomeHyrax knows whether you're home
  • Mobile data → tunnel right away.
  • On Wi-Fi the app briefly knocks on the address directly (max. 0.8 s). Answer → you're home, the page loads directly and the app remembers this Wi-Fi.
  • Other Wi-Fi (hotel, office) → tunnel right away without knocking. If the tunnel fails there, it tries the direct route after all (e.g. new router at home).
  • Loading directly fails → it switches to the tunnel by itself.
  • The Wi-Fi is recognized by address range, router address and domain – not by its name, so HomeHyrax needs no location permission.

Tip: a foreign Wi-Fi with the same default network as yours (e.g. another FRITZ!Box with 192.168.178.x) where something happens to answer at the target address is taken for home. Remedy: use your own address range at home (e.g. 10.20.30.0/24) or set the entry to VPN Always.

Help

First step: “Test connection”

On the tunnel card tap Test connection. For Tailscale it shows per entry whether the address is in a shared network, which device carries it (direct or via relay), whether it answers and whether the target can be reached. Details shows the Tailscale log with Copy log.

WireGuard problems
Message / behaviorCause and fix
“No reply from the home network”Router not reachable from outside: DS-Lite/CGNAT → Tailscale. Otherwise check port forwarding and Endpoint.
Home network address not foundDynDNS/MyFRITZ! address wrong or not active.
Tunnel up, page doesn't loadAddress not in AllowedIPs – add your home network.
Works with one phone, not with twoSame key on both – one connection per phone.
Tailscale problems
ResultCause and fix
Not in any shared networkRoute not advertised or not approved in the admin console.
Router offlineSubnet router off or key expired – disable key expiry.
Tunnel OK, connection failedRouter doesn't forward: enable IP forwarding, check firewall, update Tailscale.
Sign-in hangsDifferent account than the subnet router – use the same one.

Via a Tailscale relay (DERP) it is slower, but works and stays end-to-end encrypted.

Still stuck?

Parts of a page missing? Those addresses must be in the tunnel too. After a crash, HomeHyrax shows a report with Copy – nothing is uploaded. Write to info@camperflower.de or open an issue on GitHub.

Security & privacy

Your keys stay on your phone

Encrypted

Keys and passwords AES-GCM with Android Keystore.

Nothing uploaded

No account, no logs, no ads, no tracking.

Locked down

Local proxy with a new password on every start.

Privacy policy

Open source · Apache-2.0

Under the hood

A Go core (wireguard-go, gVisor, Tailscale tsnet) inside the app – without Android's VpnService.

WebViewlocal proxy 127.0.0.1
Camera playerRTSP via local port
Switchsingle request
➜
wgbridge (Go)routing per target: in AllowedIPs / route → tunnel, otherwise direct
➜
WireGuarduserspace netstack
Tailscaletsnet, subnet routes
Directeverything else
Build it yourself
git clone https://github.com/matthiasharzheim/homehyrax
cd homehyrax
export ANDROID_HOME=/path/to/sdk
export ANDROID_NDK_HOME=$ANDROID_HOME/ndk/28.2.13676358
./build-go.sh                      # Go tests + gomobile → AAR
./gradlew lintRelease assembleRelease

The Go tests run against a real second WireGuard peer and a Tailscale test server in-process.

FAQ

What does it cost?

Nothing. No subscription, no ads. Tailscale is free for personal use.

Do I need an account?

Not with us. WireGuard needs none at all; Tailscale uses your Tailscale account or your own Headscale.

Can I keep my other VPN?

Yes. HomeHyrax doesn't use Android's VPN slot.

Does it drain the battery?

No. The tunnel only exists while an entry is open and is gone 90 s after closing.

iPhone?

Not at the moment – Android 8.0 and later.

Why “HomeHyrax”?

The hyrax lives in rock crevices and slips through narrow gaps – like the tunnel into your home network.

Your home in your pocket.

Free, open source, without a system VPN.