CodeCanU
← Back to products
Mobile / Flutter / Full Applications

Nerd VPN : Flutter VPN with In App Purchase, Integrated Admin Panel (iOS & Android)

Nerd VPN is a production-ready, full-stack VPN solution you can rebrand and ship to the App Store and Google Play. It bundles a Flutter mobile client, a secure Node.js + Express + Sequelize REST API, and a Nuxt admin dashboard — plus a multi-protocol VPN engine supporting WireGuard, IKEv2, OpenVPN and strongSwan. Everything is server-driven: your server catalog, pricing, localization and legal pages are managed from the admin panel with no app rebuild. New in version 7.0.0 (…

19.00 USDT 64.00 USDT
Version
7.0.0

All source code listed on this site is collected from the internet. If any listing infringes your rights, please contact us and we will remove it immediately.

Description

Nerd VPN is a production-ready, full-stack VPN solution you can rebrand and ship to the App Store and Google Play. It bundles a Flutter mobile client, a secure Node.js + Express + Sequelize REST API, and a Nuxt admin dashboard — plus a multi-protocol VPN engine supporting WireGuard, IKEv2, OpenVPN and strongSwan. Everything is server-driven: your server catalog, pricing, localization and legal pages are managed from the admin panel with no app rebuild.

New in version 7.0.0 (major rewrite)

Version 7.0.0 rebuilds Nerd VPN from the ground up. The previously OpenVPN-only app is now multi-protocol (WireGuard, IKEv2, OpenVPN and strongSwan); the PHP/Laravel backend and web admin are replaced by a Node.js (Express + Sequelize) API and a Nuxt admin panel; and server configurations are now end-to-end encrypted with AES-256-GCM — the long-promised security upgrade. It stays completely login-free for end users.

Upgrading from v6.x: this is a new backend stack (Node.js, not PHP/Laravel), so deploy it fresh instead of updating your old Laravel server. Full setup steps are in the README.

Live demo

https://github.com/Laskarmedia/nerdvpn_demo

What you get (full source code)

  • Flutter mobile app (Dart 3.12+) for Android and iOS — clean architecture, Provider state management, go_router navigation, Dio networking.
  • flutter_vpn_kit — a multi-protocol VPN SDK with separate, license-aware drivers for WireGuard, IKEv2, OpenVPN and strongSwan.
  • Node.js REST API (Express 5, Sequelize 6, MySQL/MariaDB) with an interactive first-run setup wizard.
  • Nuxt admin panel (Pinia, Tailwind CSS, PWA) with a Chart.js analytics dashboard.

Key features

  • No registration or login — users connect anonymously; premium is tied to a per-device entitlement, so there are no accounts to manage.
  • Four VPN protocols — WireGuard, IKEv2, OpenVPN and strongSwan via the included flutter_vpn_kit engine. Keep it WireGuard-only (MIT) or enable all four.
  • End-to-end encrypted server catalog — server configurations are encrypted at rest with AES-256-GCM and shipped to the app as an opaque envelope. The decryption key never leaves your server and is never returned by any endpoint; only the app decrypts configs in memory at connect time.
  • Server-driven server list — add, edit and group servers by country and region from the admin panel, with country flags, connection details and speed indicators in the app.
  • In-app purchases & subscriptions — premium gating (premium servers + ad-free) with server-side receipt validation for both Google Play and Apple App Store. Product IDs are remote-configured, with an auto “Best value” paywall.
  • AdMob ads — banner monetization via google_mobile_ads, automatically hidden for premium users.
  • Multi-language & RTL — server-driven localization. Ships with English, Arabic, German, Spanish, French, Indonesian and Portuguese, including full right-to-left layout. Add or edit languages from the admin with no rebuild.
  • CMS pages — Privacy Policy, Terms and About are delivered from the backend and rendered as a native widget tree from HTML (not a WebView).
  • Light & dark theme — fully themeable with an animated dotted world-map home background.
  • Firebase built in — Analytics, Crashlytics and Performance Monitoring.
  • Role-based admin — JWT authentication with RBAC roles (super_admin, admin, editor, viewer), plus a subscriptions viewer, app config and localization manager.

Security model

  • Server configs encrypted at rest (AES-256-GCM); the master key stays on the server.
  • Anonymous device endpoints are HMAC-signed (signature, timestamp and nonce) and enforced in production.
  • Admin endpoints protected by JWT + RBAC.
  • Hardened with Helmet, a CORS allow-list and rate limiting. Secrets live in environment variables, never in source.
  • Key-rotation script included to re-encrypt the whole catalog to a new key.

Tech stack

  • Mobile: Flutter (Dart 3.12+), Provider, go_router, Dio, flutter_html, cryptography, Firebase.
  • VPN engine: flutter_vpn_kit (WireGuard, IKEv2, OpenVPN, strongSwan) — melos monorepo.
  • Backend API: Node.js 18+, Express 5, Sequelize 6, MySQL/MariaDB (SQLite for local dev), Zod validation, Pino logging.
  • Admin panel: Nuxt, Pinia, Tailwind CSS, Vite PWA, Chart.js.

Documentation & setup

Includes a detailed README and an interactive backend setup wizard that provisions the database, generates secrets, runs migrations, seeds demo data and creates your first admin account. Configure your own Firebase project with FlutterFire, point the app at your API, inject your E2E key at build time, and ship. White-label friendly — replace the logo, colors, app name and bundle IDs.

Requirements

  • Flutter SDK 3.x (Dart 3.12+), Android Studio / Xcode for builds.
  • Node.js 18+ and MySQL/MariaDB for the backend and admin panel.
  • Google Play and Apple developer accounts for store publishing and in-app purchases.
  • iOS note: Apple requires VPN apps to be published under an Apple Developer Program account enrolled as an Organization (not Individual) — see Apple’s App Review Guidelines for VPN apps.

Note: OpenVPN and strongSwan drivers are GPL-3.0; WireGuard and IKEv2 are MIT. You can ship a fully MIT-clean, WireGuard-only build by removing the two GPL drivers — documented in the README.

Changelog

Note: if you can’t see the latest update yet, it may still be in CodeCanyon review.

v7.0.0 — 14 June 2026 (major rewrite)

Changed (migration from v6.x):

  • Backend rewritten from PHP/Laravel to Node.js (Express 5 + Sequelize 6) with an interactive setup wizard — deploy fresh, not an in-place update of the old Laravel server.
  • Web admin rebuilt as a Nuxt PWA with a Chart.js dashboard and role-based access (replacing the Laravel admin).
  • VPN engine expanded from OpenVPN-only to multi-protocol: WireGuard, IKEv2, OpenVPN and strongSwan (flutter_vpn_kit, license-aware drivers).
  • Upgraded to the latest Flutter 3.x (Dart 3.12+).

New:

  • End-to-end encrypted server catalog (AES-256-GCM) — the enhanced-security upgrade; the key never leaves the server.
  • Server-side IAP receipt validation for Google Play and Apple (subscriptions stay login-free).
  • Server-driven localization in 7 languages with full RTL (en, ar, de, es, fr, id, pt) and server-driven CMS pages (Privacy, Terms, About) rendered natively from HTML, no WebView.
  • HMAC-signed anonymous device endpoints; JWT + RBAC admin; Helmet, CORS allow-list and rate limiting; key-rotation script.
  • Firebase Analytics, Crashlytics and Performance.

Kept from v6.x: no registration or login; free and premium tiers; AdMob (auto-hidden for premium); light and dark theme; multi-language; iOS and Android with app bundle builds; Provider state management; clean, easy-to-rebrand code.

Previous versions

v6.4.1 — 22 Sep 2024: Crashlytics errors on Xcode fixed (iOS); skip manual encryption for TestFlight (iOS); upgrade all packages; latest Flutter support (3.24.3 tested).

v6.4.0 — 24 Jul 2024: Upgrade billing package to 7.0.0; backend to Laravel 10 (min PHP 8.0); upgrade OpenVPN engine; fix deprecated imperative apply of Flutter Gradle plugins; AdMob 5.1.0; upgrade all dependencies.

v6.3.0 — 22 Apr 2024: Latest Flutter support (3.19.5 tested); fix UI caused by latest Flutter; fix deprecated Gradle plugin apply; AdMob 5.0.0; upgrade all dependencies.

v6.2.0 — 30 Oct 2023: Restore purchase for iOS; update all dependencies; latest Flutter support (3.13.9 tested).

v6.1.1 — 12 Aug 2023: Fix Android in-app purchase and upgrade billing 6.x; latest Flutter support (3.13.6 tested).

v6.1.0 — 12 Aug 2023: Update all dependencies; latest Flutter support (3.10.6 tested); AdMob consent for GDPR message support.

v6.0.2 — 14 Mar 2023: Fix all Text Theme deprecated issues; update all dependencies; note: VPN might not connect with the Play Store version.

v6.0.1 — 13 Jan 2023: Fix servers not showing when missing UDP/TCP; fix disconnect button.

v6.0 — 16 Dec 2022: NerdVPN rewrite; Play Billing 5, trial supported; light and dark theme; new UI and more features.

v5.11 — 14 Mar 2023: Update all dependencies.

v5.10 — 13 Jan 2023: Flutter 3.x supported; fix build error.

v5.9 — 16 Dec 2022: Flutter 3.x supported; update all dependencies.

v5.8 — 21 Feb 2022: Flutter 2.10.x supported; update all dependencies.

v5.7 — 9 Dec 2021: iOS fixes; fix some layout bugs.

v5.6 — 24 Oct 2021: Fix wrong protocol on admin panel; fix loaded protocol at app launch; fix iOS VPN with authentication; small bug fixes.

v5.5 — 23 Oct 2021: Fix disconnection bugs; fix ad bugs; add Facebook ad mediation.

v5.4 — 20 Oct 2021: New instruction link; fix ad size; bug fixes.

v5.3 — 17 Oct 2021: Add App Tracking Transparency; fix subscription file; ad on disconnect dialog; small fixes.

v5.2 — 13 Oct 2021: Fix bugs that prevented connecting to servers.

v5.1 — 9 Oct 2021: Compatible with Flutter 2.5.x; fix native VPN engine; fix AdMob deprecation; other fixes.

v5.0 — 7 Jul 2021: Rewrite engine with native functions; bug fixes.

v4.0 — 27 Mar 2021: iOS support; migrated to null-safety; rewritten instructions; UI improvements; animations; many bug fixes.

v3.1: Latest Flutter supported; rewrite instructions; bug fixes.

v3.0: Faster admin panel; multi-language; mobile server pagination; optimize admin and mobile.

v2.2: Whitelist app; AdMob safety (bypassed IP); private guide.

v2.1 — 2 Oct 2020: Fix random API.

v2.0 — 1 Oct 2020: Make mobile setup super easy; fix API source code; provide admin demo.

v1.2 — 30 Sep 2020: Fix admin web bug; simple setup video tutorial; APKs accessible via the video instructions link.

v1.0 — 29 Sep 2020: First release.

Nerd VPN : Flutter VPN with In App Purchase, Integrated Admin Panel (iOS & Android)

19.00 USDT 64.00 USDT
Buy now

After successful payment, you will receive a download link for the source code