Skip to content

VPNBaron CLI

VPNBaron CLI puts the whole VPN in your terminal. Sign in once, then connect to any location with one command: vpnbaron connect uk1. It speaks every VPNBaron protocol, including the stealth ones that get through networks that block VPNs, and it’s built for servers, SSH sessions and scripts.

One command to connect

Pick a server by its short ID or just its name: vpnbaron connect london.

Stealth built in

Hysteria2 and VLESS Reality included. If a network blocks one, it switches to the other by itself.

Made for servers and scripts

Works over SSH, with clear exit codes for scripts and tab completion for every command.

One connection, two ways

Shares its connection with the VPNBaron app: connect in one and the other shows it.

VPNBaron CLI in a terminal: listing the servers, connecting to London over Hysteria2 and showing the status

1. Install

You need Ubuntu 24.04 or newer, Debian 13 or newer, or a distribution based on them, on a regular 64-bit PC or a 64-bit ARM computer.

VPNBaron CLI comes with the VPNBaron app. If you already have the app, skip to step 2. Otherwise run:

Terminal window
sudo apt install -y curl
curl -fsSL https://vpnbaron.com/download/linux/install.sh | sh

You also need a VPNBaron account with an active plan. If you don’t have one, sign up and choose a plan.

2. Sign in

$ vpnbaron login
Email: you@example.com
We sent a 6-digit code to you@example.com. (Check spam if it doesn't arrive.)
Code: 123456
✓ Signed in as you@example.com — VPNBaron Premium Yearly until 2027-06-03

There’s no password: the code arrives in your email and expires after 5 minutes. The command keeps its own sign-in, separate from the app’s, readable only by you (on Linux, in ~/.config/vpnbaron).

3. Find a server

$ vpnbaron servers
ID LOCATION
uk1 London, United Kingdom
ca1 Montreal, Canada
de1 Frankfurt, Germany
us1stream Los Angeles, United States
…
br1 Sao Paulo, Brazil offline
Protocols: udp, tcp (OpenVPN) · hy2 (Hysteria2) · vless
Connect: vpnbaron connect <ID> [-p udp|tcp|hy2|vless]

Each server has a short ID, the easiest way to pick one.

4. Connect

$ vpnbaron connect uk1
Connecting to London, United Kingdom via Hysteria2…
Establishing stealth tunnel (Hysteria2)
✓ Connected to London — your IP is 51.195.252.254

Instead of the ID you can use a city or a country, in any case and with or without accents: vpnbaron connect london, vpnbaron connect los-angeles, vpnbaron connect germany or vpnbaron connect de. If several servers match, it lists them so you can pick one by ID.

The command returns as soon as you’re connected; the connection keeps running.

Choosing the protocol

Add -p and a protocol:

-pProtocolBest for
udpOpenVPN UDPEveryday use on ordinary networks
tcpOpenVPN TCPNetworks that block OpenVPN UDP
hy2Hysteria2Speed, especially over long distances or patchy connections
vlessVLESS RealityNetworks that block VPNs: it looks like ordinary web browsing
Terminal window
vpnbaron connect us1stream -p vless

Without -p, it uses the protocol that last worked, Hysteria2 the first time. If that one doesn’t get through, it tries the stealth protocols (Hysteria2, then VLESS Reality) by itself and tells you.

5. Check and disconnect

$ vpnbaron status
● Connected to London, United Kingdom (uk1) via Hysteria2 — 12 min
IP 51.195.252.254
$ vpnbaron disconnect
Disconnected.

vpnbaron c and vpnbaron d are short for connect and disconnect. In scripts, vpnbaron status ends with exit code 0 when connected and 1 when not:

Terminal window
vpnbaron status >/dev/null && echo "protected"

Away from the desktop (SSH)

On Linux, when you’re not at the computer’s own desktop (for example over SSH), connecting and disconnecting ask for an administrator’s password. Or run the command with sudo, which uses your sign-in, not root’s:

Terminal window
sudo vpnbaron connect uk1

Kill switch

The kill switch is a VPNBaron app setting: turn it on in the app’s Settings. Connections made with VPNBaron CLI run without it.

Tab completion

On Linux, bash and zsh complete commands, server IDs and protocols when you press Tab: vpnbaron connect u then Tab lists uk1 us1 us2 us3 us1stream.

Help and the connection log

vpnbaron help lists the commands; vpnbaron help connect explains one. On Linux, the full connection log is in the system journal:

Terminal window
sudo journalctl -u vpnbaron

Signing out, updating, uninstalling

  • vpnbaron logout signs out. A running connection stays up; vpnbaron disconnect ends it.
  • To update on Linux, run the install command again.
  • To uninstall on Linux, run sudo apt remove vpnbaron. That removes the app too.

Need help?

Contact support with your system and its version, the command you ran and what it printed.