Skip to content

High-performance Adaptive Kernel · Fully open source

Speed, measured.Trust, open source.

Hako is the proxy core that powers Clash. Built on proven mihomo and retuned for Apple NetworkExtension constraints, it handles traffic on your device—with performance measured on real hardware and its complete source code open for anyone to inspect.

Current product core

mihomo 1.19.30
Latest open-source SDKHako v1.19.30-hako.1 ↗
iOSiPadOSmacOStvOS

The heart of Clash

Trust belongs
where your traffic flows.

Clash makes the network feel simple. Hako is the part that actually handles connections, DNS, and rules. It does not ask you to trust a promise: its runtime boundaries are built into a fully open-source implementation anyone can inspect.

01

Apple public APIs only

Hako runs inside NetworkExtension and moves packets through the public NEPacketTunnelFlow API—without private APIs or file-descriptor tricks.

02

Control stays on-device

Status, traffic, connections, and logs travel over an app-private local channel, with no extra network-accessible controller.

03

Profiles stay with the client

Hako never downloads or stores profile URLs or credentials. The client prepares the runtime configuration; Hako applies its rules.

Measured on an iPad Pro (M2)

No “should be fast.”
See how fast it ran.

924 MbpsPublic-network download

545 Mbps up · 5 ms latency

18.7 MiBCore memory at speed

Lightweight under high throughput

16.49 GB30-minute pressure run

0 disconnects · 0 packet loss · 0 crashes

39.6 MiB400 concurrent connections

Within a 50 MiB test budget

Speed tests cannot exceed the available bandwidth of the test network. These figures come from a controlled run on the stated device, network, and build; actual performance varies with device, route, and configuration.

Open source · independently reviewable

Performance can be measured.
Security should be inspectable.

Hako follows stable mihomo releases only, and Clash currently runs 1.19.30. The complete Hako core is open source under GPL-3.0, with each SDK release, source version, and build artifact tied to the same tagged snapshot.

Current product coremihomo 1.19.30

Open-source release across all five Apple slices

Latest open-source SDKv1.19.30-hako.1

Complete source and build artifact are on GitHub

Apple architectures5 slices

iOS device and simulator, macOS, tvOS device and simulator

A proven data plane

The Clash capabilities you know,
inside Apple’s system boundaries.

Protocols

Connect to the routes you use

Shadowsocks, VMess, VLESS, Trojan, Snell, Hysteria2, TUIC, WireGuard, AnyTLS, SSH, and more.

DNS

Resolution follows the rules too

DoH, DoT, DoQ, fake-IP, traffic sniffing, and per-domain resolver policies.

Routing

Direct when it should be direct

domain, IP-CIDR, GEOIP, GEOSITE, RULE-SET, sub-rules, and logical rules.

Policy groups

Select, test, and fail over

select, url-test, fallback, load-balance, health checks, and remote providers.

Local control

Runtime state stays visible

Status, traffic, connections, proxies, logs, latency tests, and connection control remain available to the app locally.

Platform differences

macOS adds process rules

macOS can match process names, executable paths, and UIDs; signing-ID and team-ID matching remain unavailable. In Packet Tunnel mode, iPhone, iPad, and Apple TV do not expose per-app or per-process identity.

Do not take our word for it

Want the code? Read it.

Inspect the implementation, pin a release, or report a security issue privately. Verifying Hako requires no one’s permission.