Apple public APIs only
Hako runs inside NetworkExtension and moves packets through the public NEPacketTunnelFlow API—without private APIs or file-descriptor tricks.
High-performance Adaptive Kernel · Fully open source
Hako is the proxy core that powers Clash. Built on proven mihomo and retuned for Apple NetworkExtension constraints, it handles traffic on your device—with performance measured on real hardware and its complete source code open for anyone to inspect.
The heart of Clash
Clash makes the network feel simple. Hako is the part that actually handles connections, DNS, and rules. It does not ask you to trust a promise: its runtime boundaries are built into a fully open-source implementation anyone can inspect.
Hako runs inside NetworkExtension and moves packets through the public NEPacketTunnelFlow API—without private APIs or file-descriptor tricks.
Status, traffic, connections, and logs travel over an app-private local channel, with no extra network-accessible controller.
Hako never downloads or stores profile URLs or credentials. The client prepares the runtime configuration; Hako applies its rules.
Measured on an iPad Pro (M2)
545 Mbps up · 5 ms latency
Lightweight under high throughput
0 disconnects · 0 packet loss · 0 crashes
Within a 50 MiB test budget
Speed tests cannot exceed the available bandwidth of the test network. These figures come from a controlled run on the stated device, network, and build; actual performance varies with device, route, and configuration.
Open source · independently reviewable
Hako follows stable mihomo releases only, and Clash currently runs 1.19.30. The complete Hako core is open source under GPL-3.0, with each SDK release, source version, and build artifact tied to the same tagged snapshot.
Open-source release across all five Apple slices
Complete source and build artifact are on GitHub
iOS device and simulator, macOS, tvOS device and simulator
A proven data plane
Shadowsocks, VMess, VLESS, Trojan, Snell, Hysteria2, TUIC, WireGuard, AnyTLS, SSH, and more.
DoH, DoT, DoQ, fake-IP, traffic sniffing, and per-domain resolver policies.
domain, IP-CIDR, GEOIP, GEOSITE, RULE-SET, sub-rules, and logical rules.
select, url-test, fallback, load-balance, health checks, and remote providers.
Status, traffic, connections, proxies, logs, latency tests, and connection control remain available to the app locally.
macOS can match process names, executable paths, and UIDs; signing-ID and team-ID matching remain unavailable. In Packet Tunnel mode, iPhone, iPad, and Apple TV do not expose per-app or per-process identity.
Do not take our word for it
Inspect the implementation, pin a release, or report a security issue privately. Verifying Hako requires no one’s permission.