Hiddify on Windows

Step-by-step Windows setup for RookVPN using the Hiddify desktop client.

Download the latest Hiddify release for Windows from the official GitHub project page. Run the installer and approve the Windows VPN profile when prompted — without admin approval, the tunnel cannot start.

Import subscription

Copy your RookVPN subscription URL from the dashboard or rookvpn.com/free. In Hiddify, use Import from URL, paste the link, and wait for profiles to sync. Select a node (Helsinki, Montreal, Nuremberg) and click Connect.

TUN vs system proxy

For full-device coverage, enable TUN mode in Hiddify settings. System proxy alone may not route all desktop apps. Games, IDEs, and some Microsoft Store apps often bypass per-app proxy rules.

Verify on Windows

Invoke-RestMethod -Uri 'https://rookvpn.com/check/api/ip/address'

Compare with WebRTC and DNS leak tests in your browser. See the full Hiddify setup guide and VPN leak testing guide.

Check the result

After Connect, open the VPN leak test in the same Windows session. The public IP should be the exit you selected, not the ISP address you wrote down while disconnected. Then run the curl IP command from PowerShell. If Edge and PowerShell disagree, Hiddify is tunneling the browser and not the terminal, or the reverse. TUN mode is what puts both on the tunnel. System proxy mode leaves other apps on the old route.

WebRTC is separate. A matching IP with a LAN address still listed in the WebRTC check is not a finished setup. Restrict WebRTC or confirm the client forces it into the tunnel, then reload the test. IPv6 that still shows the ISP prefix means the profile is IPv4-only. Disable IPv6 on the adapter or pick a profile that carries it.

Do this again after a Hiddify upgrade. Windows updates have a habit of replacing the VPN profile prompt, and a client that looks connected can be a system proxy with a dead TUN adapter.