Chute Overview
Chute is a web development and proxy utility, available on macOS, iOS, tvOS, and Android. The Android app runs the same engine ported to Kotlin (KLNEKit-K), so one configuration file serves every platform. It is designed for developers and therefore requires professional knowledge to use.
Features
- High Performance, Stability, and Efficiency: Chute can smoothly handle all network traffic with industrial-grade stability using minimum system resources.
- Flexible Rule System: You can write forwarding rules based on domain name, IP CIDR, GeoIP, IP ASN, process name, and more. Logical combination rules (AND, OR, NOT) are also supported. Chute can automatically proxy requests to other servers using HTTP/HTTPS/SOCKS5/SOCKS5-TLS/Shadowsocks/ShadowsocksR/Trojan/VMess/VLESS/AnyTLS/TUIC/Hysteria2/WireGuard/AmneziaWG/ShadowTLS/MASQUE/SSH protocols. Surge-private protocols — most notably Snell — are not supported; the configuration importer, and Chute Mac's share-link importer, skip such entries with a warning.
- HTTPS Decryption: HTTPS traffic can be decrypted by man-in-the-middle attack. The certificate generator of Chute Mac and Chute iOS will help you generate a CA certificate trusted by your operating system for debugging purposes; Chute Android imports a PKCS#12 of your own instead.
- Local DNS Mapping: Chute supports local-customized DNS mapping. Its multiple functional modules, including wildcard, alias and custom DNS server, DoH (DNS-over-HTTPS), DoT (DNS-over-TLS), DoQ (DNS-over-QUIC), and DoH3 (DNS-over-HTTP/3), will be able to satisfy various needs. All DNS servers are queried simultaneously to boost performance.
- Policy Group: You may categorize several proxies as a group and a policy will be employed in accordance with the grouping. A policy group can be configured as Auto URL Test (select policy based on benchmarking URL access speed), Fallback (select by availability priority), Load Balance (distribute across proxies with
round-robin,consistent-hashing, orsticky-sessions), SSID (select policy based on Wi-Fi SSID), and Manual Select. - HTTP Rewrite: You can rewrite HTTP/HTTPS requests to another URL using customized rules, or simply block the requests;
- Mock Response: You can return mock data to matched HTTP/HTTPS requests without reaching the real server;
- Body Rewrite: Search and replace content in HTTP request and response bodies using regex or JSONPath expressions, or transform them with jq programs;
- Protocol Sniffing: Chute can detect the actual protocol of a connection (HTTP/TLS/QUIC) and apply rules accordingly;
- JavaScript Scripting: Run custom JavaScript scripts for advanced request/response modification, DNS resolution, custom rule matching, and scheduled tasks;
- HTTP Control API & Web Console: Chute provides an embedded HTTP Control API and a Web Console for monitoring and controlling the proxy runtime;
- Notification Reporting: Chute detects patterns in connection failures, proxy unavailability, traffic surges, config update failures, and policy group switches. It dispatches structured events to the Chute app, which may present system notifications for significant anomalies;
- Remote Dashboard: Chute Dashboard may connect to remote Chute iOS, Chute Mac, Chute tvOS or Chute Android instances via USB (Chute iOS and Chute Android) or network.
- Full IPv6 Support: All functions work in IPv6 environment.
- UDP Relay: Chute's tunnel — Chute iOS, Chute tvOS, Chute Android in VPN mode and Chute Mac in Enhanced Mode — and its SOCKS5 listener could send your UDP packet with proxy, you can improve your game experience with SOCKS5/SOCKS5-TLS/Shadowsocks/ShadowsocksR/Trojan/VMess/VLESS/TUIC/Hysteria2/WireGuard/AmneziaWG/AnyTLS/MASQUE proxies.
Chute Mac Exclusive Features
- Enhanced Mode: Chute can handle all network traffic from applications that do not explicitly support web proxy, using either a virtual network interface (VIF) via privileged helper or a PacketTunnel VPN system extension. See Enhanced Mode for details.
Chute iOS and Chute tvOS
Both run as a system VPN, as Chute Android does in its VPN mode:
- All functions work on cellular network.
- Capture all HTTP/HTTPS/TCP/UDP traffic from any apps on your device, and redirect to HTTP/HTTPS/SOCKS5/SOCKS5-TLS/Shadowsocks/ShadowsocksR/Trojan/VMess/VLESS/AnyTLS/TUIC/Hysteria2/WireGuard/AmneziaWG/ShadowTLS/MASQUE/SSH proxy servers following highly configurable rules, even if the app does not follow system proxy settings.
- Override system DNS settings even on cellular network.
- Monitor and analyze network requests by connecting Chute Dashboard — to Chute iOS via Wi-Fi or USB cables, to Chute tvOS over the network. You can even examine cellular network requests when connecting via USB cables.
Chute Android Exclusive Features
- Per-app proxy: route every app, only the selected apps, or every app except the selected ones through the VPN.
- Local Proxy service mode: run the HTTP and SOCKS5 listeners without a system VPN, for other apps or devices to point at.
- Start on Boot, Restrict to Wi-Fi (auto-pause on metered networks), a Quick Settings tile, home-screen shortcuts and a widget, and broadcast intents and a Tasker/Locale plugin for automation apps.
- See Getting Started on Android for the first run and the platform differences.