Overview
ZeroTier for Magisk, developed by eventlOwOp, ports the enterprise peer-to-peer (P2P) mesh networking daemon zerotier-one directly to rooted Android devices. Standard user-space ZeroTier clients for Android utilize the system’s VpnService API, which forces Android to treat ZeroTier as a standard VPN—monopolizing the single available VPN slot and preventing users from running privacy VPNs, WireGuard profiles, or local DNS adblockers simultaneously.
This Magisk module launches zerotier-one at the Linux kernel and network stack level. It initializes a persistent virtual Ethernet interface on boot, allowing your Android phone to participate directly in private, encrypted LANs across mobile data and Wi-Fi networks without occupying the system VPN slot.
Prerequisites & Compatibility
- Android Version: Android 9.0 (Pie, API 28) and newer.
- CPU Architecture:
arm64-v8a(AArch64)armeabi-v7a(32-bit ARM)
- Root Solution: Magisk (stable or canary).
There are no documented module conflicts; it coexists peacefully alongside third-party VPN apps and firewall managers.
Key Architecture & Features
- Background Daemon: The native daemon launches during late boot (
service.sh) and maintains lightweight, peer-to-peer UDP punch-through connections to remote nodes (laptops, home NAS, servers). - Private Root Servers (Planets & Moons): For users operating private, self-hosted ZeroTier controllers (such as ztncui or custom planet definitions), custom network topology files can be deployed directly to
/data/adb/zerotier/home/planet. - SSO Integration: The AArch64 GCC build supports single sign-on authentication (
zeroidc) for enterprise identity verification.
Installation & Configuration
- Download the
zerotier-magisk.zipmodule package and the companioncontroller.apkfrom the GitHub releases page. - Install the module in Magisk and install the Controller APK as a standard user application.
- Reboot your device to initialize the networking daemon.
- Launch the ZeroTier Controller app:
- Enter your 16-character ZeroTier Network ID.
- Tap Join.
- Log into your ZeroTier network management web console (e.g.
my.zerotier.com) and authorize the new Android node. - The Android device will receive a private IP address and can immediately ping or access services across the mesh network.
- Active daemon states, keys, and planet configurations reside in:
/data/adb/zerotier/
Troubleshooting & Verification
- Node Not Appearing in ZeroTier Console:
- Verify that the daemon is active from an ADB root shell:
su -c zerotier-cli status # Should return: 200 info <node_id> <version> ONLINE
- Verify that the daemon is active from an ADB root shell:
- Custom Planet Not Loading: If using a custom root server, place your compiled
planetbinary in/data/adb/zerotier/home/planet, restart the daemon (su -c killall zerotier-one), and verify connectivity usingzerotier-cli peers.