secure-vpn

SECURITY

Secure configuration delivery

The pairing website is designed to minimize exposure: it shows a short-lived code while the supported client completes the protected configuration claim.

Public website boundaries

The website does not require an account and does not publish a reusable VPN subscription address. Opening a pairing link in a normal browser provides only a general explanation; it does not redeem the pairing code or return configuration details.

Pairing safeguards

  • Pairing codes expire after ten minutes.
  • Each code supports one successful claim.
  • Pairing responses use no-store cache controls.
  • The client completes the claim through a separate protected request.
  • Expired, previously used or invalid codes are rejected.

Device-authenticated sessions

Compatible client releases use a separate P-256 device credential for each app installation. After the device proves possession of that credential, the service can issue short-lived access and refresh credentials bound to that installation.

Proof-of-possession checks help ensure that copying a credential value alone is not enough to act as the enrolled installation. The client and service determine compatibility during authentication; the website and QR code do not carry or enforce a client version.

Responsible use

For ongoing use, operate and maintain a server you control. Any configuration offered through this website is intended for temporary connections or testing and is not guaranteed to remain available.

Review the pairing instructions and contact technical support if setup does not complete.