3x-ui3x-ui

MASQUE

Serve MASQUE (CONNECT-IP) inbounds in 3x-ui, connect outbounds to MASQUE servers, and reach Cloudflare WARP over MASQUE.

MASQUE carries IP packets over HTTP/3 (or HTTP/2) with the CONNECT-IP method, so a client gets a full layer-3 tunnel that looks like ordinary HTTPS traffic. xray-core serves it natively; 3x-ui offers it as an inbound protocol, an outbound protocol, and the matching masque transport they both ride on.

Inbound

FieldDescription
ClientsEach client logs in with its email and password (HTTP Basic auth). Traffic, quotas, IP limits and expiry work like any other multi-user protocol.
Address poolPrefixes the tunnel addresses are leased from — at most one IPv4 and one IPv6 (default 10.14.0.1/24, fd14::1/64). The pool size caps how many clients can be connected at once.
MTUTunnel MTU, 1280–65535; leave empty for the core default.
PathRequest path the server answers on (default /.well-known/masque/ip/*/*/).
SecurityAlways TLS. The ALPN picks the listeners: h3 serves HTTP/3 on UDP, h2 serves HTTP/2 on TCP, and both together serve both.

MASQUE has no share-link format, so MASQUE inbounds get no link, QR code or Clash entry. Clients get a ready-to-import config from the JSON subscription: a masque outbound that authenticates with the client's email and password.

Outbound

Pick masque as the outbound protocol, then set:

FieldDescription
Address / PortThe MASQUE server.
Remote DNSOptional DNS server IPs queried inside the tunnel.
Host / PathAuthority and path of the CONNECT-IP request; the path must match the server's.
Username / PasswordHTTP Basic credentials — on a 3x-ui server, the client's email and password.
HeadersExtra request headers.
TLSRequired. An ALPN of h2 alone switches to HTTP/2 over TCP; otherwise HTTP/3 is used.

WARP over MASQUE

The quickest way is Xray → Outbounds → WARP → Add WARP over MASQUE outbound: the panel registers a separate WARP device, enrolls a MASQUE key for it and adds a ready warp-masque outbound (or refreshes the existing one). Your WireGuard WARP registration is not touched. To set it up by hand instead:

Turn on WARP in the masque transport to reach Cloudflare WARP through its MASQUE endpoint instead of WireGuard. It takes a WARP registration enrolled for MASQUE:

FieldDescription
Private keyThe enrolled ECDSA P-256 private key (PEM, or base64 DER).
Endpoint public keyCloudflare's endpoint public key returned by the enrollment.
Tunnel addressesThe IPv4 and IPv6 addresses Cloudflare assigned to the registration.

Host and path then default to Cloudflare's endpoint, and WARP can't be combined with a username or password. Point the outbound at the endpoint address from your enrollment and set the TLS server name to consumer-masque.cloudflareclient.com.

On this page