snitun
SNI proxy with TCP multiplexer
Decision gist · record as of 2026-08-14
Yes, if you need an encrypted SNI proxy with multiplexing and are comfortable with GPL v3 licensing. The package is production-stable, actively maintained, has low install friction, and no known vulnerabilities. Install only if your project can comply with copyleft terms and your deployment targets Python 3.13+.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.13 or later.
- For aes-gcm-siv cipher support, OpenSSL 3.0+ is required on the server side.
- Low install friction with only two runtime dependencies (aiohttp and cryptography).
License · maintenance · safety
GPL v3 (copyleft) — Licensed under GPL v3 (copyleft). Any application that links or distributes this package must also be released under a compatible open-source license; proprietary or closed-source projects cannot use it without legal review.
last release 2026-06-29 (46 days) · last repo commit 2026-08-01 · 121 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 667,606 downloads/mo, #5,419 on PyPI
Alternatives
Verify before relying
pip install snitun
from snitun.multiplexer import SniTunMultiplexer
from aiohttp import ClientSession
# Typically instantiated within an async context with Fernet token and AES configuration
multiplexer = SniTunMultiplexer(fernet_token, aes_key, aes_iv)- Whether the package provides server-side SniTun implementation or only client-side multiplexer components.
- Specific performance characteristics or throughput limits for the multiplexer under typical load.
- Whether session master and token generation are included or must be implemented separately.
What it is and what it does
SniTun is a proxy and multiplexer library that secures TCP connections by encrypting them end-to-end using Fernet tokens for authentication and AES (CBC, GCM, or GCM-SIV) for payload encryption. It intercepts external TLS/SNI connections, validates clients via a challenge-response handshake, and forwards traffic through an encrypted multiplexed channel to local endpoints. The library handles protocol versioning, flow control (pause/resume), and connection lifecycle management (new, data, close, ping messages) within the multiplexer frame format.
The package is designed for scenarios where you need to proxy TLS connections through an untrusted network while maintaining encryption and authentication. It uses aiohttp for async HTTP operations and cryptography for all encryption primitives. Configuration is flexible via environment variables for queue sizes and watermarks. The implementation supports both stateful (AES-GCM) and stateless-nonce (AES-GCM-SIV) modes, with the latter providing nonce-misuse resistance at the cost of requiring OpenSSL 3.0+.
Use it for
- Secure remote access to local services by proxying TLS connections through an encrypted multiplexed tunnel with token-based authentication.
- Building a home automation or IoT gateway that forwards external device connections to internal services without exposing them directly.
- Implementing a VPN-like proxy layer where multiple clients share a single encrypted multiplexer session with per-connection isolation.
- Protecting against man-in-the-middle attacks on untrusted networks by encrypting both the multiplexer protocol and the forwarded TLS payload.
- Multi-tenant or multi-device scenarios where clients authenticate via Fernet tokens and the server routes traffic based on SNI hostname matching.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need an encrypted SNI proxy with multiplexing and are comfortable with GPL v3 licensing.
The package is production-stable, actively maintained, has low install friction, and no known vulnerabilities. Install only if your project can comply with copyleft terms and your deployment targets Python 3.13+.
Install
snitun on PyPI
Before you install
Low install friction with only two runtime dependencies (aiohttp and cryptography). Active maintenance with a recent commit on 2026-08-01 and production-stable status. Requires Python 3.13 or later.
Requires Python 3.13 or later. For aes-gcm-siv cipher support, OpenSSL 3.0+ is required on the server side.
License in practice
Licensed under GPL v3 (copyleft). Any application that links or distributes this package must also be released under a compatible open-source license; proprietary or closed-source projects cannot use it without legal review.
Quickstart
pip install snitun
from snitun.multiplexer import SniTunMultiplexer
from aiohttp import ClientSession
# Typically instantiated within an async context with Fernet token and AES configuration
multiplexer = SniTunMultiplexer(fernet_token, aes_key, aes_iv)
Verify before relying
- Whether the package provides server-side SniTun implementation or only client-side multiplexer components.
- Specific performance characteristics or throughput limits for the multiplexer under typical load.
- Whether session master and token generation are included or must be implemented separately.
Package facts
| License | GPL v3 copyleft |
| Python support | Supports the current Python release >=3.13 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesaiohttpcryptography |
| Maintenance | Actively maintained 46 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 667,606 / month, #5,419 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: End Users/DesktopLicense :: OSI Approved :: GNU General Public License v3 (GPLv3)Operating System :: OS IndependentProgramming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Internet :: Proxy ServersTopic :: Software Development :: Libraries :: Python Modules |
Evidence: snitun-0.47.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “SNI proxy multiplexer”
- snitunSniTun is an SNI proxy with TCP multiplexer that encrypts traffic…
- mulpyplexerMulpyplexer applies method calls and attribute access to lists of…
- libtmuxlibtmux provides a typed Python API to control tmux (the terminal…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also miscreant · fernet · cryptg · aioping · TgCrypto · pproxy · srp · oscrypto · django-fernet-fields-v2 · keyrings.cryptfile