VPN for Android: always-on, battery and security
How Android runs a VPN, why the connection drops in the background, what Always-on VPN does and how to verify an APK.
October 1, 2026 · 2 min readAndroid gives VPN apps a dedicated system interface, VpnService. The app creates a virtual adapter and all of the device's traffic passes through it. That is where the familiar "app wants to set up a VPN connection" prompt and the key icon in the status bar come from.
First connection
- Install the app from the Colitu for Android page.
- Tap Connect. Android asks for VPN permission; tap OK. You are asked only once.
- The key icon in the status bar means the tunnel is up.
If you do not know your processor architecture, download the universal APK. Most recent phones are arm64-v8a; older 32-bit ones are armeabi-v7a.
Why the VPN drops in the background
Many manufacturers' skins save battery aggressively and close background services, the VPN included. What to do:
- Settings → Apps → Colitu → Battery → Unrestricted.
- On Xiaomi (MIUI/HyperOS), enable Autostart and lock the app in the recent apps list.
- On Huawei, turn off "Manage automatically" for Colitu under app launch.
- On Samsung, remove Colitu from "Sleeping apps".
Always-on VPN
Android 7 and later have a system feature called Always-on VPN: Settings → Network & internet → VPN → Colitu → gear icon. Android brings the VPN back up after a reboot or a drop.
On the same screen is Block connections without VPN (Android 8+). It acts as a system-level kill switch: if the tunnel falls, apps cannot reach the internet directly. Note that there is no internet at all until the VPN connects.
How the app picks a protocol
Colitu remembers the last protocol that worked on your network and tries it first. If it is blocked, the app moves on in the background: Hysteria2, VLESS Reality, Trojan or Shadowsocks 2022. On low-end devices the app tones down its animations so it does not waste resources.
App security
- Android Keystore. Session tokens are encrypted with a key from the Android Keystore, the system key store from which keys cannot be extracted.
- Certificate pinning. The connection to the Colitu API only accepts certificates issued from known root keys. A certificate swapped in on the network (for example by a corporate proxy) is rejected.
- Update checks. Before installing an update, the app compares the file's SHA-256 and the signing certificate's fingerprint with the release manifest.
Verifying an APK
If you downloaded the APK by hand rather than through the app, check it:
- Compare the file's SHA-256 with the value on the download page.
- For advanced users:
apksigner verify --print-certs Colitu-*.apk— the certificate's SHA-256 fingerprint must match the published one.
The app's code is open: github.com/cyberlexs/colitu-android.