Quick verdict
- What it is
- Store information collected; independent summary not yet available.
- At a glance
-
- Free to download
- In-app purchases
Categories and search queries
Official categories
- Developer Tools
- Utilities
AppCorpus categories
Key functions
| Function | Availability | Access | Scope | Evidence |
|---|---|---|---|---|
| Free app | Yes | Free | — | Store published |
| In-app purchases | Yes | Limited free | — | Store published |
Screens
No screenshots collected yet.
Pricing & paywalls
App Store
- Free to download
- In-app purchases
Ratings & reviews
App Store
-
5/510 STARS! This app LITERALLY saved my privacy from being compromised!!
RUN DONT WALK & DOWNLOAD I purchased the $50 packet WORTH EVERY FREAKING PENNY. I highly suggest if you download you purchase the upgraded version! They respect apple and their terms of use. & PROVIDE YOU WITH A LEGITIMATE LICENSE That apple respects!! So no legal issues in studying and blocking the third parties requests & their connections to gather your data or should i say compromise 😅, you can BLOCK EACH ONE COMPLETELY! I am honestly amazed beyond words and I sincerely want to thank every developer & brainstormers that contributed in the creation of this miraculous app. Literal Geniuses!!!. you guys are phenomenal, thank you so much!:)
laurereynolds135447 · 31 Jul 2026
-
5/5it can improve Nintendo online network
I use this software to improve the online network for Nintendo game consoles. This software can use the personal hotspot of the mobile phone to accelerate the game console, which is really easy to use.
peaelephant · 31 Jul 2026
-
5/5Excellent
It's not so much a tool as a window to a new world. As commercial software, meeting user needs and adding more protocol support are essential! Hopefully, the developers will listen to user feedback and make this software a true SWISS ARMY knife among proxy software.
ImShos · 31 Jul 2026
-
5/5Great app!
Hello Dear Dev. please consider adding OpenVPN Protocol. It’s useful when user wants to wrap OpenVPN traffic through SSH, HTTP, etc. Specially in countries with heavy crackdown on internet like iran. please add Vless Protocol. And for last please add monthly payment option. u can help peaple all over the world. Thank you.
shaahin.ak · 31 Jul 2026
-
5/5Great App
There are many malicious comments due to payment issues. But it’s a great app for sure. Even after so many years, Surge has always been at the forefront.
Mikeshake1993 · 31 Jul 2026
Privacy & accessibility
App Store
Privacy
- Data Linked to You — App Functionality — Contact Info — Email Address Developer declared
- Data Linked to You — Contact Info Developer declared
- Data Not Linked to You — Analytics — Diagnostics — Crash Data Developer declared
- Data Not Linked to You — Analytics — Diagnostics — Performance Data Developer declared
- Data Not Linked to You — Analytics — Usage Data — Product Interaction Developer declared
- Data Not Linked to You — Diagnostics Developer declared
- Data Not Linked to You — Usage Data Developer declared
Accessibility
No accessibility labels collected yet.
Versions
App Store
-
5.11.0
Smart Group This is a new type of policy group, driven by our carefully designed algorithm engine, which can automatically select the appropriate policy from the sub-policies of this policy group. The goal of the Smart policy group is to replace the original automatic testing groups (url/load-balance/fallback), greatly optimizing the experience while minimizing the need for manual intervention in policy groups. Users only need to put the available policies into this group. For details, see: https://kb.nssurge.com/surge-knowledge-base/guidelines/smart-group Rule System - Overall performance optimization of the rule system. - Significant optimization of the indexing algorithm in large domain rule sets, improving the search efficiency by more than ten times for rule sets with more than 100,000 rules. - Corrected the issue where sub-rules of logical rules within a rule set could not be covered by the `no-resolve` and `extended-matching` parameters of the rule set. - Added a new rule type `DOMAIN-WILDCARD`, supporting `?` and `*` domain name matching. - `DOMAIN-SET` and `RULE-SET` are changed to strict validation. If there are invalid lines in the file, the entire rule set will be invalidated to avoid problems caused by misuse. IPv6 - The behavior of the `ipv6-vif` parameter has been modified. When set to always, IPv6 functionality will be enabled even if `ipv6=true` is not set. - Added a warning for the `ipv6-vif=always` parameter. - Adjusted the automatic retry mechanism. Accessing IPv6 addresses in a non-IPv6 network will no longer enter the retry process, and the request will fail immediately (solving the problem of some applications stalling when IPv6 VIF is enabled in a non-IPv6 environment, but the application will still continue to send IPv6 requests). Other Optimizations - Enhanced `$notification.post`, adding support for media resources, sound hints, and automatic dismissal. - Optimized WireGuard failure handling. - Reduced the power consumption of the TUIC protocol during sleep. - Improved the precision of time statistics in the request log system, now accurate to µs level. - Optimized various abnormal retry mechanisms, avoiding high resource usage caused by continuous retry in the face of some specific problems. For operations that need to be retried continuously (such as WireGuard reconnection, Ponte server reporting to iCloud), Surge will now retry after 0.1s, 0.5s, 1s, 5s, 10s, 30s after an error. - Optimized the caching system for external resources. - Added the profile line modifier `#!REQUIREMENT`. - When the current network is found to be managed by Surge Mac Gateway, Surge iOS will now automatically pause. (This can be adjusted via the auto-suspend option, enabled by default.) - Optimized TUN takeover and specific app performance compatibility issues. - Optimized memory usage, infrequently used and large scripts will not be cached in memory anymore. - The network diagnostics page adds SSID/BSSID with copy functionality. - Now, when uploading logs in the log interface, the engine currently running will automatically generate the most recent verbose logs (the new version has cached 256KB of logs in memory), so when reporting problems, you can upload directly without needing to reproduce in verbose mode. - For external resources related to policy groups and script types, the maximum size is now limited to 2MB, to avoid memory overflow in case of configuration errors. Check the knowledge base for complete release note.
-
5.11.1
- Optimize the matching performance of small rule sets, especially evident on older model CPUs. - The external resource update page can display error information generated by rule set processing. - Automatically ignore invalid empty lines in the rule set. - Corrected the issue where applying temporary rules and then experiencing a policy change does not disrupt existing connections. - Corrected the issue when using Ponte policy within Smart group, if the target device is itself, it failed to automatically switch to DIRECT policy. - Corrected the problem of incorrect time displayed in request logs for Ponte device requests. - Corrected crashes that may occur when external policy groups change. - Fixed an issue where configuration upgrade functionality did not correctly take effect for managed configurations and enterprise configurations. - During Smart group initialization phase, no longer displays most frequently used tags to avoid misunderstanding. - Fixed an issue where local script files could not be automatically reloaded after being edited. - Optimized indexing process for large rule sets. - Limited maximum number of files for iCloud background auto auto-sync to 200 to avoid memory usage issues. - Fixed potential UI display issues when adjusting policies through remote controller。
-
5.11.2
- Now you can see the number of times a rule has been used in the rule list. - Optimized the implementation method of blocking QUIC traffic to increase the likelihood of clients correctly falling back. - The Smart group will use the SUBSTITUTE policy (DIRECT) instead of failing directly when there are no sub-policies. - Fixed an issue where the `server-cert-fingerprint-sha256` parameter was not effective for TLS-like protocols with sni=off settings. - Added a new rule type `HOSTNAME-TYPE`, used to determine the type of request hostname. Optional values are: `IPv4`, `IPv6`, `DOMAIN`, `SIMPLE`. (`SIMPLE` refers to hostnames without a dot, such as `localhost`) - Optimized DNS request logs. Now more information is displayed. Additionally, if DIRECT policy connects directly without triggering DNS in the rule system, related DNS logs can still be shown. - When deleting a policy that is being used by a policy group, it is now allowed to delete it directly and automatically remove it from all policy groups. - Bug fixes and other Improvements.
-
5.11.3
- Support turning off Surge via widgets/Shortcuts when the always-on switch is turned on. - Support turning on Surge via widgets/Shortcuts when the Surge VPN Profile is not selected (or when other VPNs are running). - Fix an issue where DOMAIN-SUFFIX rules may become invalid if duplicate DOMAIN and DOMAIN-SUFFIX rules are included in the rule set. - Optimizations related to No Default Route mode, significantly improving usability. - Other bug fixes.
-
5.12.0
- New subscription feature: Custom policy group icons. - Refactor the Surge tvOS profile deployment process using CloudKit, significantly improving stability. Please note that both Surge iOS and tvOS need to be upgraded to the latest version before you can use the profile deployment feature, and the tvOS version needs to be launched once for registration. - When using the add rule function in the request list, you can choose to add it to an existing rule set. (Supports local rule files and inline rule sets). - Optimized behavior when enabling IPv6 VIF under No Default Route mode. - Other optimizations and bug fixes.
-
5.13.0
- Control Center Widget: On iOS 18, you can now quickly toggle Surge in the Control Center. - New Icon: Sapphire. - Added Ponte diagnostic function for quickly locating Ponte-related issues, accessible from the Ponte device page. - Port Hopping: Hysteria2 and TUIC protocol now support port hopping to improve ISP's QoS issues with UDP. See the server documentation for details. - Added `[General]` parameter `show-error-page`, which is used to control whether Surge's HTTP error page is displayed when an error occurs. This parameter is enabled by default, and the behavior is consistent with previous versions. - Bug fixes.
-
5.14.0
New Features - Added pre-matching rules for low-overhead request rejection. Please refer to the documentation for details. https://manual.nssurge.com/policy/reject.html - Body Rewrite supports using JQ expressions to manipulate JSON. - The shadowsocks protocol adds support for the `2022-blake3-aes-256-gcm` and `2022-blake3-aes-128-gcm` encryption modes - Adapted icon mode for iOS 18. - New Control Center control for HTTP capture. - DNS now supports system search domain settings - Added parameter proxy-restricted-to-lan to restrict the proxy to only accept devices from the same subnet - When updating external resources, ETag will be recorded and sent; re-download will not be triggered if the resource has not changed Improvements - Overall optimization and improvement of UDP forwarding. - The policy group list view supports configuring custom icons. - Resolved issues with real-time display on iOS 18 - Optimized the display effect of policy group icons - Improved HTTP engine compatibility with non-standard requests - More explicit error prompts when Surge is activated without a network connection - Enhanced error handling logic for encrypted DNS, retrying immediately upon encountering errors - Added warning messages for excessive [Host] entries - The URL-REGEX rule now supports `extended-matching` tags. - Allow the use of Ponte policy as an underlying proxy. Bug Fixes - Fixed an issue where Control Center/home screen widgets would still show as active even when Surge was turned off - Fixed a memory leak issue in encrypted DNS under certain errors - Corrected subscription cycle constraint errors for new icons - Other bug fixes
-
5.14.1
Bug fixes
-
5.14.2
- Bug fixes and improvements.
-
5.14.3
New Feature: Port Forwarding - This feature is commonly used in development and debugging scenarios such as connecting to servers like MariaDB using SSH. #!REQUIREMENT upgrade - Now provides three simple notations: #!IOS-ONLY, #!MACOS-ONLY, and #!TVOS-ONLY. - Content disabled by this end-of-line comment can now be displayed and edited in the UI. It will appear as disabled when conditions are not met, and if enabled, restrictions will be automatically removed. [Host] Optimization - [Host] section supports configuration using DOMAIN-SET and RULE-SET to improve matching efficiency. Use case: Other Improvements - Added option icmp-forwarding, enabled by default. - Optimize using Smart policy groups as the underlying proxy. Now, in this usage scenario, the characteristics of Smart policy groups can be fully utilized. - Bug fixes and other improvements.
-
5.14.4
- When enabling the HTTP capture switch, all active connections will now be forcibly interrupted to ensure that no requests are missed due to existing long connections. - Optimized compatibility with some QUIC clients, such as Lark. - Fixed an issue where download data bytes in statistics was incorrect after modifying the request HTTP using scripts or other mechanisms. - Adjusted the priority of processing logic when forwarding QUIC. Now, for a proxy policy that does not support UDP forwarding, it will prioritize considering QUIC Block before falling back to DIRECT or REJECT. - Bug fixes and other improvements.
-
5.14.5
- Support DNS over TLS. - Bug fixes and performance improvements.
-
5.14.6
- Added [General] parameter `block-quic`, which is used to globally override the behavior of blocking QUIC traffic. - Optimized the text and JSON viewer in the request inspector, now supporting large files and code highlighting. - Rewrote HTTP script-related implementation; it now performs better and uses less memory when handling large bodies. - Supports SNI extraction for gQUIC. - Refactored traffic statistics functionality; now, even if you haven't entered the main program for a long time, you won't have to wait a long time when accessing the traffic statistics page. - Added export feature to traffic statistics. - Other detail optimizations and bug fixes.
-
5.15.0
Built with the Surge v6 core, synchronizing new features from Surge Mac 6.0, including: - Significant performance improvements to the Surge VIF Engine (free update) - Improvements to Surge Smart Group (free update for unlocked users) - Surge Ponte 2.0 - Multiple Channels (requires use with Surge Mac 6.0) - Snell v5 (feature subscription required) For full details, please refer to the Surge Mac 6 release notes: https://kb.nssurge.com/surge-knowledge-base/release-notes/surge-mac-6-release-note
-
5.15.1
Bug fixes
-
5.15.2
Bug fixes and minor enhancements
-
5.16.0
- Adapted to the latest iOS version interface style. - Added external IP and NAT type detection features.
-
5.16.1
- Added bandwidth testing feature - Bug fixes
-
5.16.2
Bug fixes
-
5.16.3
Bug fixes and other improvements
-
5.17.0
- Optimize various UI details and presentation on iOS 26. - New subscription feature: compatible with the AnyTLS (v2) proxy protocol. - Supports Hysteria 2 Salamander obfuscation mode. - Optimize QUIC SNI extraction to support extracting SNI from incomplete initial packets - On the policy group page, long-press a policy group with a profile that has a policy-path to update the policy group directly. - The QUIC block behavior for all proxy protocols has now been adjusted to be blocked by default.
-
5.17.1
Added - Experimental support for the Trust Tunnel protocol - Added an Intent for profile switching; you can now switch the current Surge profile directly in Shortcuts - Added a Debug message toggle on the Ponte page; when enabled, detailed connection status messages will be shown during the Ponte connection process - Support for directly referencing hosted profiles without first adding the hosted profile as a local profile (i.e., the Linked Profile feature on macOS) - Enterprise/Team license can now be used on the tvOS version Improved - All parameters for the throughput test are now customizable - Added a workaround to address an issue on newer iOS versions where, after long scripts run for a while, setTimeout is throttled by the system’s resource saving and can fire at most once every 2 seconds - Policy groups no longer validate the validity of sub-policy names. If a referenced sub-policy does not exist, the non-existent options will be automatically hidden at runtime. The include-other-group parameter has been adjusted similarly. Note: using a non-existent policy in [Rule] will still trigger a hard profile error prompt. Fixed - Fixed a compatibility issue between AnyTLS and some servers (when reuse is enabled, if a previous request fails, subsequent requests could hang) - Fixed a rare crash when using QUIC-type protocols or h3 DNS - Fixed an issue where only the small card view could display the “Update External Resources” menu item
-
5.18.0
(Because the interval since the last subscription feature update was too long, all users whose subscription feature expiration date is after December 11, 2025 have been granted a free 3-month extension.) New subscription feature: Logbook, used to persistently record various events that occur, - Currently includes events such as engine start and stop, network switching, script start and stop, script timeout, etc. - The logbook is specially optimized for script debugging, making it easy to view a script’s input, output, and logs. At the same time, scripts can proactively write content to the logbook using $surge.logbook("content") - Surge Dashboard on Surge Mac can read the logbook content of remote Surge instances, and all script execution details can be accessed remotely Other improvements - Added support for the X25519MLKEM768 post-quantum hybrid key exchange group for all TLS-related features (such as proxy protocols, MITM, DoH/DoT/DoH3) - Improved the $persistentStore management page, adding operations such as search, import/export, and delete all - Refactored memory management for the QUIC protocol to resolve an issue where, under certain circumstances, QUIC-based protocols could experience sudden excessive memory usage that caused Surge to be terminated by the system - Fixed a memory leak when using Trust Tunnel - Fixed a crash that could occur with extremely low probability - Fixed an issue where API requests could get stuck when HTTP API TLS is enabled - Fixed some UI detail issues
-
5.19.0
Adjustments to the Feature Update Subscription for Surge iOS Since the introduction of the feature update subscription mechanism for Surge iOS, we have aimed to maintain a reasonable balance between continuously evolving the product’s capabilities and ensuring a reliable long-term user experience. After evaluation, we have decided to make the following adjustments: 1. All newly added proxy protocol compatibility support in the future will no longer be included within the scope of the feature update subscription, and will be available directly to all users. 2. TrustTunnel, which is currently supported on an experimental basis, will also not be subject to subscription restrictions and can be used directly. We believe that protocol compatibility should be a fundamental capability provided in a stable, long-term manner, rather than a phased incremental feature. This means that, in the future, users will not need to worry about the availability of basic protocol support due to their subscription status; new protocol compatibility capabilities will also be made available to all users more directly and continuously. After this adjustment, subscription updates will focus more on new advanced features, while protocol compatibility itself will be maintained as a long-term foundational capability of the product. At the same time, the proxy protocol ecosystem itself is also constantly changing. Some protocols continue to evolve, while others gradually fall out of mainstream use cases. To ensure the long-term maintainability of Surge’s codebase and the overall quality of the product, we will also take actual usage into account when placing certain legacy protocols into maintenance freeze, or gradually ending support for them in the future. We will handle related adjustments as cautiously as possible and provide explanations in advance, in order to minimize the impact on existing user profiles and user experience. Thank you all for your continued support and feedback. --------------------- * Added HTTP/2 CONNECT proxy support. You can configure HTTP/2-based CONNECT proxy connections via the h2-connect type. * HTTP, HTTPS, HTTP/2 CONNECT, and TrustTunnel proxies now support custom request headers. * HTTP/2 CONNECT and the TrustTunnel proxy now support multiplexing. Because too many sub-connections multiplexed over the same TCP connection may cause performance issues, by default up to 3 sub-connections are allowed. This can be adjusted via the policy parameter `max-streams`. * The storage logic for icon configuration in the iOS version has been adjusted. Now, when the profile is editable, it will preferentially be written into the profile to ensure interoperability with the Mac version. Only when the profile is read-only will a separate UI profile be used for storage. * Fixed an issue where sending SNI did not strictly comply with RFC6066. Now, when an IP address is used as the hostname, the IP address will not be sent as SNI. * Fixed an issue where crashes could occur when using ShadowTLS with certain servers. * Fixed an issue where, when the Logbook contained a very large amount of data, it could not be viewed remotely via the Dashboard. * Other performance optimization and minor enhancements.
-
5.20.0
· 20 Jul 2026
### Tailscale Support Surge now supports Tailscale as a policy. With this feature, Surge can join your Tailscale tailnet directly and route selected traffic through Tailscale peers using the existing Surge rule system. You can use Tailscale IPs, and tailnet-only services together with Surge policies, policy groups, DNS handling, traffic logging, and rule-based routing. Please check the manual for more information: https://manual.nssurge.com/policy/tailscale.html ### Snell v6 Introduced Snell v6, featuring PSK-derived deployment-level protocol diversity that generates unique traffic characteristics for each deployment, reducing reliance on a single protocol fingerprint while preserving Snell’s core goals of performance, deployment simplicity, accurate error reporting, and full TCP semantics. Snell v6 also adds new IPv4/IPv6 network stack controls including dns-ip-preference and multi-address listen support, and is currently available for beta testing. Please check our blog for more information: https://nssurge.com/blog/snell-v6/ ### Codebase Refactoring We have completed a comprehensive review of Surge’s core functionality and resolved numerous implementation issues, edge cases, and long-standing inconsistencies. This ongoing refactoring effort improves maintainability and helps provide a more robust foundation for future development. ### WireGuard WireGuard policies now use a dedicated native RTT test when no DNS server is configured, making them suitable for peer-to-peer access without requiring a reachable test URL. When a DNS server is configured, the policy is treated as a standard outbound proxy and continues to use the regular URL test process. WireGuard runtime information and diagnostics have also been updated to reflect the applicable testing mode. ### Minor Improvements - The Smart Group algorithm has been reviewed and upgraded, fixing several potential issues. - The `header` parameter for the HTTP proxy type can now override original fields, including Host field. - Added Gecko obfuscation support for Hysteria2, configured using the `gecko-password` parameter. - All TLS proxy protocols now support customizing ALPN using the `alpn` field. - When local DNS mapping is specified using server, multiple DNS servers can now be configured. - URL scheme actions are now supported in Surge Mac. Check manual for more information. - Enable the keep-alive mechanism for all QUIC-based protocols ### Other - Optimize the performance of Surge Ponte. - The UI configuration interface has been completed for the recently added proxy protocol parameters, including Tailscale. - Fixed an issue where the `header` parameter did not take effect in HTTP/1.1 CONNECT mode. - Fix some issues when using SF Symbols for policy group icons. - Fixed compatibility issues between DoH3 and some servers.
Alternatives
- Network Sniffer — Same category + similar ratings
- Debug Anywhere — Same category + similar ratings
Availability by market
- US
Data quality & evidence
- Page completeness
- Live store listing
- Last verified
- 31 Jul 2026
- Sources
- App Store
- Independent summary has not been published yet.
- Screenshots: not yet collected