I spent nine months living and working in China, and the VPN apps I had installed from the App Store failed one after another, usually within days.
The app opens, shows "connecting", and never gets there. That's not bad luck and not a bad app: it's the predictable result of how those apps are built and distributed. What kept me online for the whole nine months was much simpler and, at first, felt too simple to trust: a website where I copied a connection key, and a small client app called Happ where I pasted it.
This article is that method, written down. First why the App Store apps fail, then what a key is and why a generic client behaves differently, then the exact setup to do before you land. It's written by a member of the 404 VPN team; the experience is first-hand, the conclusions are mine, and none of it's a guarantee that any connection works from every Chinese network on every day.
store unreachable no updates
known protocol handshake spotted
provider's servers blocked too
key + generic client nothing to update
└─ paste, connecta key you can read as text a client that accepts any key a second protocol as backup └─ none of these need a store once they are on the device
Why App Store VPN apps fail in China
Two separate reasons, and they stack.
The first is distribution. In 2017 Apple removed VPN apps from its Chinese App Store, saying at the time that it was complying with local regulations. If your Apple ID is set to China, the apps are simply not there. If your Apple ID is foreign, you can install them at home, but once you're inside China the store itself, the update servers and the app's own website are usually unreachable. The moment an app needs an update, a new login or a fresh configuration from its servers, it's stuck. Google Play is unreachable from Chinese networks altogether, so on Android the picture is the same with fewer ways around it.
The second is the connection. Most commercial apps use OpenVPN, IKEv2 or WireGuard. Those protocols have recognizable traffic patterns, and the national filter identifies them by the shape of the handshake rather than by the address. The connection either never completes or drops after a few minutes. Some providers add obfuscation on top, and some of those work for a while; in my experience "a while" meant days, after which the app was back on "connecting". Whatever a provider promises on its website, its servers, its updates and its protocol are all one well-known package, and a well-known package is exactly what the filter is built to recognize.
The pattern over nine months: every branded app I tried failed, some on the first day, some after a week. What each failure looks like and what to try in the moment is in VPN not working in China? Fix it by symptom.
app ships a fixed server list └─ those addresses are known app ships a recognisable protocol └─ the shape is known app needs its own store to update └─ the store is unreachable
What worked: a key, and a client that belongs to no one
The alternative is to separate the two things an app bundles together: the client software and the connection.
A key is a single line of text, starting with vless://, that describes one connection: the server address, an identifier, and how the traffic should be dressed so that it looks like an ordinary HTTPS session with a website. You get it from a provider's website or dashboard, the way you would copy a password. It isn't an app, and it doesn't need a store.
Happ is a small client for iPhone and Android that accepts any such key. It isn't tied to a provider. It has no account of its own and nothing to fetch from a VPN company's servers: you paste a key, tap connect, and that is the whole relationship. Hiddify, v2rayNG and NekoBox are open-source clients that work the same way, and any of them will do; Happ is simply the one I used.
Why this held up when the apps didn't, as far as I can tell: the connection is built to be indistinguishable from normal encrypted web traffic, so there's no signature to match; the client is generic, so there's no brand to target; and nothing depends on an app store or on a provider's servers being reachable from inside China. When one key stopped working, I pasted another. The app never had to change. How this kind of connection differs from the classic protocols is explained in What is VLESS and Reality.
None of this is invisibility. Filtering rules change, some days are worse than others, and a key that works today can stop tomorrow. The difference is that recovery takes one paste instead of an app update that can't download.
a key you copy as text └─ nothing to look up in a store a client that takes any key └─ not tied to one provider a transport shaped like plain HTTPS
How to set up a VPN key in Happ before you fly
Everything below has to happen at home. Inside China you'll most likely be unable to install the client, open the provider's website, or read a support article, including this one.
- Install the client. On iPhone, Happ from the App Store while your Apple ID is still on a foreign region. On Android, Happ, Hiddify or v2rayNG. Install two if you can; they're small.
- Get your key. Sign up with a provider that gives you a plain
vless://key or a subscription link, and copy it. With 404 VPN it's the key in your dashboard. - Paste it into the client: "Add", "Import from clipboard" or a QR code, depending on the app. Connect.
- Check that it works: open What Is My IP and confirm that the address and the country changed.
- Save the key somewhere that doesn't need the internet: the notes app, a screenshot, a message to yourself. If a key stops working you need a second one or a way to get a fresh one, which is what a subscription link is for: it refreshes the list of keys on its own. Use it instead of a single key whenever your provider offers one.
- Switch roaming on for a few minutes as a test, so that you know how to reach the outside internet if everything else fails on a bad day.
The iPhone-specific part, including what to do about the Apple ID region, is in VPN for China on iPhone.
[ ] client installed while stores work [ ] keys saved as plain text [ ] both protocols tested at home [ ] offline maps downloaded [ ] a second way to reach people
What it looked like day to day
Mobile data on a Chinese SIM and the Wi-Fi where I lived and worked: the key-in-Happ setup was what I used every day for the whole stay. Not every day was smooth. Some evenings a key would slow down or drop and I would switch to another; around holidays things got noticeably worse for a day or two and then recovered on their own. What never came back after the first weeks was the situation where the app itself was the problem.
If I had to compress nine months into one sentence: the apps failed because they're a known package, and the key worked because it isn't.
mornings usually fine evenings slower, flakier hotel Wi-Fi strictest mobile data most forgiving └─ "not working" often meant "not working right now"
If something won't load and you can't tell whether the problem is the network, the connection type or the tunnel, describe it.
Help me work out what is wrong with my
connection while traveling.
Where I am: (city, province in China).
Connection: (roaming / travel eSIM / local SIM /
hotel Wi-Fi).
What will not load: (list it).
What loads fine: (list it).
Tunnel: (on and connected / on but will not
connect / not using one).
Tell me which part is failing: the network
itself, the way I am connected, or the tunnel.
And what to check first.
If the data is not enough, ask instead of
guessing.
What this doesn't solve
It doesn't make hotel Wi-Fi faster. It doesn't replace WeChat and Alipay, which you need regardless and which work without any of this. It doesn't help on the days when a network refuses every encrypted connection; on those days roaming is the fallback, and the full picture of your options is in VPN for China: what to know before you land. And it isn't legal advice: unapproved international connections are a violation in China, enforcement has historically been aimed at sellers rather than travelers, and the decision is yours. Check the current rules before you go.
404 VPN works exactly the way described here: you get a vless:// key or a subscription link in your dashboard and paste it into Happ, Hiddify or any client you prefer, and there's also our own Android app if you'd rather not paste anything. The free plan is enough to run every step above before you fly. We don't promise availability from every network in China on every day; we do recommend setting up at home, keeping a second key, and treating roaming as your backup. Start on the home page.