Skip to content

VMess — Xray-core ​

VMess 是经典的 AEAD-only V2Ray 协议。Xray-core 仅支持 AEAD 变体 —— 不支持基于 alterId 的 MD5-AEAD 模式。运行时启动时会打印弃用提示,建议改用 VLESS 加密(infra/conf/vmess.go:65, 124)。

入站 ​

"protocol": "vmess" 入站的 settings:

字段类型默认值允许值描述
users[]json.RawMessage—<user object array> | …入站账户列表;对象形状与 clients 相同。两个键均可使用。
clients[]json.RawMessage(required)<user object array>可接受的用户列表。每个条目包含 VMess 账户字段(id、security、experiments)与通用用户字段(email、level)。
default*VMessDefaultConfig(unset)VMessDefaultConfig传入连接不匹配任何已配置 client 时使用的默认设置。目前只有 level 字段。

源码: infra/conf/vmess.go:57-61 · 锚定版本 v26.9.9 (52a412d)

default ​

字段类型默认值允许值描述
levelbyte0<byte>fallback 用户使用的策略等级。

源码: infra/conf/vmess.go:46-48 · 锚定版本 v26.9.9 (52a412d)

clients[] —— 用户对象 ​

clients[] 中每个条目都是 VMessAccount 加通用用户字段(email、level):

字段类型默认值允许值描述
idstring(required)<UUID>用户 UUID。规范 8-4-4-4-12 形式或去掉横线的 hex;加载时解析并重规范化。
securitystringautoauto | aes-128-gcm | chacha20-poly1305VMess 载荷的对称加密。auto 在 x86+AES-NI 上选 AES-GCM,其他平台选 ChaCha20。无法识别的值会静默回退到 auto。
experimentsstring(unset)<string>以逗号分隔的实验性标志,会被转发到协议层(在 protobuf 中作为 TestsEnabled)。

源码: infra/conf/vmess.go:18-22 · 锚定版本 v26.9.9 (52a412d)

出站 ​

"protocol": "vmess" 出站的 settings:

字段类型默认值允许值描述
address*Address(unset)<host>简化形式 —— 服务器主机名或 IP。设置后内部自动构造 vnext。
portuint16(required with address)<port>服务器端口(简化形式)。
leveluint320<uint32>用户等级(简化形式)。
emailstring(unset)<string>统计中显示的用户标识。
idstring(required with address)<UUID>用户 UUID(简化形式)。
securitystringautoauto | aes-128-gcm | chacha20-poly1305可选加密集合与入站 client 一致。
experimentsstring(unset)<string>转发到服务端的实验性标志。
vnext[]*VMessOutboundTarget(use simplified shape)[{address,port,users:[user]}]完整形式 —— 必须恰好一个服务器恰好一个用户。

源码: infra/conf/vmess.go:111-120 · 锚定版本 v26.9.9 (52a412d)

简化形式 vs. vnext

出站接受 要么 简化形式(address、port、id、security ……),要么 完整的 vnext 形式。简化形式会被改写成单条 vnext 数组(infra/conf/vmess.go:127-135)。完整形式必须 恰好 一个服务器一个用户 —— 多端点请使用多个 VMess 出站加路由负载均衡器。

示例 ​

最小入站:

json
{
  "inbounds": [
    {
      "tag": "vmess-in",
      "listen": "0.0.0.0",
      "port": 443,
      "protocol": "vmess",
      "settings": {
        "clients": [
          { "id": "a3482e88-686a-4a58-8126-99c9df64b7bf", "email": "alice", "security": "auto" }
        ]
      },
      "streamSettings": { "network": "tcp", "security": "tls" }
    }
  ]
}

简化出站:

json
{
  "outbounds": [
    {
      "tag": "vmess-out",
      "protocol": "vmess",
      "settings": {
        "address": "example.com",
        "port": 443,
        "id": "a3482e88-686a-4a58-8126-99c9df64b7bf",
        "security": "auto"
      },
      "streamSettings": { "network": "ws", "security": "tls", "wsSettings": { "path": "/vm" } }
    }
  ]
}

说明 ​

  • Xray 的 VMess 只支持 AEAD。配置结构体里没有 alterId 字段;为 V2Ray 编写的配置应删除 "alterId": <n> —— MD5-AEAD 模式无论如何都会被拒绝。
  • security: "auto" 是安全的默认值:在带 AES-NI 的平台选 AES-GCM,其他平台选 ChaCha20-Poly1305。未知的 security 字符串会静默回退到 auto(infra/conf/vmess.go:34-35)。
  • none 与 zero 不是可识别的 security 取值 —— 带这些值的配置会静默得到 auto。
  • 每次加载 VMess 入站或出站时都会打印启动期弃用横幅("VMess (with no Forward Secrecy, etc.)",infra/conf/vmess.go:65, 124)。推荐用带 mlkem768x25519plus 加密的 VLESS 替代。

跨内核说明 ​

  • sing-box 用 users[].uuid 替代 clients[].id,并暴露 Xray 所没有的 alter_id(snake_case)、global_padding、authenticated_length 选项。参见 VMess — sing-box。
  • mihomo 采用单一 proxy 对象形态,用 cipher 字段表示加密选择,并在出站上暴露 UDP 编码开关(xudp、packet-addr、packet-encoding)。参见 VMess — mihomo。

源码: infra/conf/vmess.go:18-120 · v26.9.9 (52a412d)

由 Argsment 出品的 Core Tutorial