Skip to content

How it works

From sign-up to secure browsing

KatLink is built on WireGuard, a modern open-source VPN protocol. Here's what happens at each step.
  1. 1

    You create an account

    Your KatLink account holds your packages, devices and receipts. You'll use it to download configurations and check your usage.

  2. 2

    You get a package

    Buy a package through secure checkout, or redeem a voucher. Payments are confirmed directly with our payment provider before anything is activated.

  3. 3

    We create your device configuration

    For each device, KatLink generates a WireGuard configuration with its own key and a private VPN address, and registers it with a KatLink gateway.

  4. 4

    You connect with WireGuard

    Scan the QR code from your dashboard with the WireGuard app, or import the configuration file, then switch the tunnel on.

  5. 5

    Your traffic goes through the gateway

    While connected, your device's internet traffic travels encrypted to the gateway, which forwards it to the internet and sends the replies back through the tunnel.

  6. 6

    Access ends automatically

    When your package's time or data runs out, the gateway removes your device's access. You don't need to do anything, and nothing renews on its own.

What happens when you connect
  1. Your device

    Phone, tablet or computer running the free WireGuard app.

  2. Encrypted WireGuard tunnel
  3. KatLink gateway

    Decrypts your traffic and forwards it to the internet.

  4. Regular internet traffic
  5. The internet

    Websites see the gateway's IP address instead of yours.

The network you're on can see that you're connected to KatLink, but not the content of your traffic.

About WireGuard

WireGuard is an open-source VPN protocol designed to be simple and fast. It uses well-studied cryptography: Curve25519 for key exchange and ChaCha20-Poly1305 for encryption. Its small codebase has been widely reviewed, and the official apps are free.

Your configuration is a key

Each configuration contains a private key unique to that device. Anyone holding the file could use your package, so keep it to yourself. If a device is lost or you think a configuration was copied, contact support so we can replace it.

What the gateway measures

The gateway counts how much data each device sends and receives, and when it last connected. That's how your dashboard shows usage and how data-based packages are enforced. The gateway doesn't record which websites you visit or the content of your traffic. See the Privacy Policy for details.