Set Up a Persistent Tor Proxy on Android Using Orbot and VPN Service
14 min read
Step‑by‑step guide to route all Android traffic through Tor using Orbot’s VPN mode, without rooting. Includes verification, troubleshooting, and device‑specific tips.
October 10, 2026 21:00
Many Android users want the anonymity of the Tor network but hesitate because they think it requires rooting or complex configuration. This tutorial shows exactly how to turn any Android device into a system‑wide Tor proxy using the free Orbot app and Android’s built‑in VPN service. The result is a persistent, “set‑and‑forget” connection that routes all traffic (except for VPN‑exempt apps) through Tor without touching the operating system.
Before you start
- Battery: Make sure the device is charged to at least 50 % or keep it plugged in. Tor routing is CPU‑intensive and can drain the battery quickly.
- Network: Connect to a stable Wi‑Fi network. Mobile data works too, but you may incur higher data usage.
- Google Play Services: Orbot is available on the Play Store, but you can also download the F‑Droid version if you prefer a fully open‑source source.
- Backup: No system files are touched, but if you rely on a VPN‑exempt app (e.g., banking), note that its traffic will now travel through Tor, which may trigger security alerts.
Step 1 – Install Orbot
- Open the
Google Play Store (or F‑Droid if you prefer).
- Search for Orbot: Tor for Android by the Guardian Project.
- Tap Install and wait for the download to finish.
- After installation, launch Orbot. The first launch will ask for permission to create a VPN connection – this is essential for the system‑wide routing.
Why Orbot? It bundles the official Tor daemon, handles bridge selection, and provides a simple UI for enabling a VPN tunnel that forces all traffic through Tor. Because it uses Android’s VPNService API, no root access is needed.
Step 2 – Configure Orbot for a Persistent Tor Circuit
- In Orbot’s main screen, tap the gear icon to open Settings.
- Under Tor Settings, enable “Enable Bridges” if you are on a network that blocks Tor (e.g., public Wi‑Fi). The default
obfs4 bridge works in most cases.
- Scroll down to VPN Settings and toggle “VPN Mode” on.
- Optionally, enable “Allow VPN Apps” and add any apps you want to keep out of Tor (e.g., banking or payment apps). This list is device‑specific; leave it empty for full‑system routing.
- Return to the main screen and press the Power button (the large ON/OFF toggle). Orbot will ask for VPN permission – tap Allow.
- Wait a few seconds while Orbot builds the first Tor circuit. You’ll see a green shield and a notification saying “Tor is ON”.
What you just did: Orbot creates a virtual network interface (a VPN tunnel) that forwards every packet to the Tor daemon running locally. The daemon then routes the traffic through three random Tor relays, giving you anonymity.
Step 3 – Make the Tor VPN Persistent Across Reboots
Android does not automatically restart VPN connections after a reboot. Orbot provides a built‑in option to restore the VPN state.
- Open Orbot Settings again (gear icon → General).
- Enable “Start on boot”. This tells Orbot to launch automatically when the device boots.
- Enable “Enable VPN on start”. With this flag, Orbot will attempt to re‑establish the VPN immediately after it starts.
- Optionally, disable battery optimisation for Orbot: Settings > Apps > Orbot > Battery > Unrestricted. This prevents Android from killing the service while the screen is off.
After a reboot, you should see the Orbot notification appear within a minute, indicating that the Tor circuit is active again. If the notification does not appear, open Orbot manually and toggle the VPN switch.
Step 4 – Verify That All Traffic Is Going Through Tor
Verification is crucial. If a single app bypasses the VPN, your anonymity could be compromised.
- Open a web browser (Chrome, Firefox, or the built‑in Android Browser).
- Navigate to
https://check.torproject.org. The page will display a message like “Congratulations. This browser is configured to use Tor.” If you see this, the VPN tunnel is working.
- To double‑check, open a terminal emulator (or use Termux) and run
curl https://ifconfig.me. The IP address shown should belong to an exit node (often ending in .onion‑related ranges) and not your ISP’s address.
- For a quick app‑level test, install the “Orbot – Tor Status” widget (available from the app drawer). The widget shows the current IP address used by Tor.
If the check page reports a direct connection, the VPN is not active. Re‑open Orbot, ensure the VPN toggle is green, and verify that no other VPN app is conflicting.
Step 5 – Using Tor with Specific Apps
Most Android apps respect the system VPN, but a few use their own network stacks (e.g., some games or VoIP apps). Here’s how to handle them:
- Apps that work out‑of‑the‑box: Chrome, Firefox, Telegram, Signal, Reddit, etc. They automatically inherit the Tor route.
- Apps that ignore VPN: Some banking apps use certificate pinning and may refuse to run over Tor. You can either add them to the “VPN Exempt” list (Settings → VPN Settings → Allow VPN Apps) or accept that they will not work while Tor is on.
- Tor‑only apps: Orbot ships with the “Orweb” browser, which is pre‑configured for Tor. Use it for quick, private browsing if you prefer a dedicated client.
Step 6 – Advanced: Using Bridges and Pluggable Transports
In restrictive environments (e.g., corporate Wi‑Fi, schools), Tor traffic may be blocked. Bridges hide the fact that you are connecting to the Tor network.
- In Orbot Settings → Tor Settings, turn on “Use custom bridges”.
- Select obfs4 from the dropdown. If you have a personal bridge address, paste it into the text field.
- Save and restart Tor by toggling the main switch off and on again.
- Run the verification step again. If the check page now reports a Tor connection, you have successfully bypassed the block.
Why bridges matter: They make Tor traffic look like normal HTTPS, which many firewalls allow.
Step 7 – Troubleshooting Common Issues
7.1 Orbot fails to start the VPN
- Cause: Another VPN app is already active.
- Fix: Go to Settings > Network & internet > VPN and disconnect any active VPN. Then return to Orbot and enable the VPN toggle.
7.2 Tor connection is extremely slow
- Cause: Tor circuits are congested or you are on a low‑bandwidth network.
- Fix: In Orbot Settings → Tor Settings, tap “New Identity” to build a fresh circuit. You can also enable “Use bridges” to reach less‑congested relays.
7.3 Certain apps stop working after Tor is enabled
- Cause: The app uses a hard‑coded proxy or certificate pinning that rejects Tor exit nodes.
- Fix: Add the app to the “VPN Exempt” list, or use the app’s built‑in proxy settings (if any) to point to
127.0.0.1:9050 – the local Tor SOCKS port.
7.4 Orbot disappears after a reboot
- Cause: Battery optimisation killed the service.
- Fix: Settings > Apps > Orbot > Battery > Unrestricted. Also verify that “Start on boot” and “Enable VPN on start” remain enabled.
Step 8 – Edge Cases and Manufacturer‑Specific quirks
Android skins sometimes modify the VPN API. Below are the most common variations.
- Samsung One UI: The system may show a “VPN always on” warning. Dismiss it and confirm that Orbot is the active VPN.
- Xiaomi MIUI: MIUI aggressively kills background services. Open Settings > Battery & performance > Manage apps > Orbot and set it to “No restrictions”.
- Huawei EMUI: EMUI may require you to enable “Allow VPN connection while locked” under Settings > Security > VPN.
If you encounter a manufacturer‑specific dialog you do not understand, the safest route is to temporarily disable the device’s power‑saving mode while setting up Orbot.
Step 9 – Maintaining Anonymity While Using Tor
- Never log in to personal accounts (e.g., Google, Facebook) while Tor is active unless you are comfortable linking your real identity to the Tor exit IP.
- Avoid downloading files that could reveal your real IP when opened (e.g., PDFs that embed metadata).
- Use HTTPS everywhere. Tor encrypts the path to the exit node, but the exit node can see unencrypted HTTP traffic.
- Consider a “New Identity” after each sensitive session. Orbot’s button creates fresh circuits, reducing correlation risk.
Step 10 – Removing Orbot and Restoring Normal Network Behavior
- Open Orbot.
- Tap the Power button to turn off the VPN.
- Optionally, go to Settings → General and disable “Start on boot” if you no longer want Orbot to launch automatically.
- If you added apps to the “VPN Exempt” list, you may clear the list to avoid future routing surprises.
All system settings revert to their pre‑Tor state; no data is lost because Orbot never modifies system files.
Final thoughts
By following this tutorial you have turned an ordinary Android phone into a portable Tor gateway without rooting or flashing custom ROMs. The setup is reversible, respects Android’s security model, and works across most manufacturers and Android versions (5.0+). Remember that Tor provides anonymity, not absolute security—always combine it with good personal security habits.