← All articles
Guides

VPN for Android: always-on, battery and security

How Android runs a VPN, why the connection drops in the background, what Always-on VPN does and how to verify an APK.

October 1, 2026 · 2 min read

Android gives VPN apps a dedicated system interface, VpnService. The app creates a virtual adapter and all of the device's traffic passes through it. That is where the familiar "app wants to set up a VPN connection" prompt and the key icon in the status bar come from.

First connection

  1. Install the app from the Colitu for Android page.
  2. Tap Connect. Android asks for VPN permission; tap OK. You are asked only once.
  3. The key icon in the status bar means the tunnel is up.

If you do not know your processor architecture, download the universal APK. Most recent phones are arm64-v8a; older 32-bit ones are armeabi-v7a.

Why the VPN drops in the background

Many manufacturers' skins save battery aggressively and close background services, the VPN included. What to do:

  • Settings → Apps → Colitu → Battery → Unrestricted.
  • On Xiaomi (MIUI/HyperOS), enable Autostart and lock the app in the recent apps list.
  • On Huawei, turn off "Manage automatically" for Colitu under app launch.
  • On Samsung, remove Colitu from "Sleeping apps".

Always-on VPN

Android 7 and later have a system feature called Always-on VPN: Settings → Network & internet → VPN → Colitu → gear icon. Android brings the VPN back up after a reboot or a drop.

On the same screen is Block connections without VPN (Android 8+). It acts as a system-level kill switch: if the tunnel falls, apps cannot reach the internet directly. Note that there is no internet at all until the VPN connects.

How the app picks a protocol

Colitu remembers the last protocol that worked on your network and tries it first. If it is blocked, the app moves on in the background: Hysteria2, VLESS Reality, Trojan or Shadowsocks 2022. On low-end devices the app tones down its animations so it does not waste resources.

App security

  • Android Keystore. Session tokens are encrypted with a key from the Android Keystore, the system key store from which keys cannot be extracted.
  • Certificate pinning. The connection to the Colitu API only accepts certificates issued from known root keys. A certificate swapped in on the network (for example by a corporate proxy) is rejected.
  • Update checks. Before installing an update, the app compares the file's SHA-256 and the signing certificate's fingerprint with the release manifest.

Verifying an APK

If you downloaded the APK by hand rather than through the app, check it:

  1. Compare the file's SHA-256 with the value on the download page.
  2. For advanced users: apksigner verify --print-certs Colitu-*.apk — the certificate's SHA-256 fingerprint must match the published one.

The app's code is open: github.com/cyberlexs/colitu-android.