China 'Airport' VPN Providers (机场): The Honest Guide
机场 (airport) providers in China sell shared Shadowsocks and V2Ray nodes for a few dollars a month. Why they collapse under work use and what to use instead.
Inside the Chinese-language VPN community, 机场 (jīchǎng, literally "airport") is the slang term for subscription proxy services that sell access to a pool of shared Shadowsocks, V2Ray, or VLESS nodes through a subscription URL. They are nothing like a commercial VPN. They are cheap, technical, popular among Chinese university students and developers, and very much not built for sustained business use.
This guide explains what an airport provider actually is, why the price is so low, what the failure modes look like, and where the boundary sits between "fine for a hobbyist" and "do not run a workday on this."
Table of contents
- What an "airport" actually is
- Why they are so cheap
- Where they fail
- Airport providers vs commercial VPNs
- Who they are right for
- Who they are wrong for
What an "airport" actually is
A 机场 provider sells a subscription, usually for between five and thirty renminbi per month, that gives the buyer a URL. The URL returns a list of proxy nodes, typically anywhere from a dozen to several hundred Shadowsocks, V2Ray, Trojan or VLESS endpoints, refreshed on a regular cadence. The buyer plugs the URL into a client like Clash, sing-box, Shadowrocket, V2rayN or Surge, and the client manages the rest: failover, latency probing, automatic node switching.
The provider does not write a desktop app, does not run customer support in any serious sense, does not publish a privacy policy, and does not promise a service level. The product is a list of endpoints. Everything else is the buyer's problem.
That model is the defining feature. The provider is buying or renting cheap servers in nearby regions (Hong Kong, Japan, Singapore, the US), running standard open-source proxy software on top, and reselling capacity. They turn over IPs as fast as the firewall burns them. The good ones do this competently; the bad ones do not, and there is no public way to tell them apart in advance.
Why they are so cheap
The math is straightforward. A small commodity VPS in Hong Kong costs the provider a few dollars per month. A hundred subscribers at fifteen renminbi each ($2) is $200 of revenue against $5 of infrastructure cost. The margin is enormous on the upside; the risk is that any of those nodes can be burned within hours during an enforcement wave, and the provider has to replace them fast enough to keep subscribers from churning.
The economics work because:
- Shared infrastructure. Hundreds of buyers ride the same nodes.
- No support burden. The community handles configuration through forums and chat groups.
- No SLA. Nodes go down; new nodes appear; nobody is owed a refund.
- No privacy guarantees. Most providers operate as semi-anonymous individuals or small teams.
- No commercial overhead. No payroll, no compliance, no audited accounting.
When you pay fifteen renminbi a month for a 机场, that is exactly what fifteen renminbi a month buys. It is not a bad deal for what it is. It is not a commercial VPN.
Where they fail
The cheap shared model has several characteristic failure modes that are not negotiable through better customer service.
Burn-and-replace cycles. When the firewall flags a node IP, the node dies for everyone on it at once. Good providers replace nodes within hours; weaker ones go dark for days. During politically sensitive weeks the cycle accelerates and even the best providers struggle.
Variable speed. A node may have ten subscribers on it one hour and a hundred the next, depending on which other nodes are down. The same node can feel snappy at noon and unusable at 8 p.m. There is no committed capacity.
Shadowsocks is increasingly detectable. The classic protocol survives now mostly on IP-rotation churn rather than on stealth, a gap the Shadowsocks vs VLESS-Reality head-to-head covers in detail. The newer providers have shifted toward VLESS-Reality and Hysteria2, but mass-market airport providers tend to lag the protocol curve by months. The basic survival logic is covered in our best protocol for China explainer.
No privacy posture. A subscription URL is a credential that identifies you to the provider. The provider can see your traffic patterns. Many providers are based in mainland China or Hong Kong, which is a meaningfully different jurisdictional posture than a Western commercial VPN. For users with sensitive work that is a category error.
No support when something breaks. The community might help on a forum. The provider rarely answers email. A configuration issue on a Wednesday afternoon before a meeting is your problem.
Airport providers vs commercial VPNs
| Property | 机场 (airport) provider | Commercial consumer VPN | Premium-routed business VPN |
|---|---|---|---|
| Price | ~$2 to $5/month | $5 to $20/month | $20+ for business plans |
| Infrastructure | Shared cheap VPSes, fast IP churn | Shared global server fleet | Private CN2 GIA or IPLC routing |
| Protocols | Shadowsocks, V2Ray, VLESS, Hysteria2 (varies) | Proprietary obfuscation on OpenVPN/WireGuard | VLESS-Reality + Hysteria2 |
| Peak-hour speed inside China | Highly variable, often poor | 5 to 25 Mbps | 100 to 500 Mbps |
| App | Bring your own (Clash, sing-box, Shadowrocket) | Polished branded apps | Branded apps + router-level deployment |
| Support | Community forums, sometimes nothing | Standard customer service | Engineering-level support |
| Privacy posture | Provider can see traffic, often opaque ownership | Stated no-logs policies, sometimes audited | No-logs by architecture |
| SLA | None | Implicit | Operational commitments |
| Best fit | Hobbyists, students, developers | Casual travellers, light remote work | Sustained work, teams, businesses |
The fair framing: airport providers are the cheapest legitimate proxy access for technical users in China. They are not a worse commercial VPN. They are a different product class, with different trade-offs.
Who they are right for
Airport providers are genuinely useful for several audiences:
- Chinese students and developers who are comfortable in Clash or sing-box, want low cost, and treat the connection as a hobby project rather than infrastructure.
- Casual personal use where the cost difference matters more than the reliability does, and a half-day outage is an inconvenience rather than a problem.
- Backup for a primary VPN. Five dollars a month for a secondary path is reasonable insurance, and the cheap providers are good at providing a different IP pool than the commercial ones.
- Travellers who already use Clash and want a familiar setup that follows them between regions.
If the workflow above describes you, an airport provider can be a fine tool. The choices in the Chinese-language community change too fast for any single recommendation to be useful for long; the well-known names this year may be gone next year, and that turnover is part of the model.
Who they are wrong for
Airport providers are the wrong primary tool for several common cases that look like they should fit but do not:
- Remote workers whose income depends on the connection. The variability is not the right risk profile for a workday of video calls.
- Teams or offices. No router-level deployment, no shared management, no admin visibility, no support escalation.
- Sensitive work where the privacy posture matters. The provider can see your traffic; you usually do not know who the provider is.
- Large file transfers, dependable video calls, or anything peak-hour. Shared infrastructure is exactly the wrong substrate for the use cases that hurt most.
The honest summary, after years of watching this category in China, is that airport providers are an excellent hobbyist tool and an outright wrong choice for production work. They are not bad products; they are correctly priced for what they are. The mistake is paying $3 a month for $3 of infrastructure and then expecting it to behave like business infrastructure.
For the wider question of which protocols, services, and routes actually survive a workday in China, the best VPN for China guide ranks the alternatives, and whether VPNs work in China covers the underlying architecture choices that separate consumer from business-grade access. The full menu of non-VPN circumvention options is in our circumvent blocked sites walkthrough.
If your day in mainland China depends on a tunnel that does not vanish during a politically sensitive week or collapse at 9 p.m. on a video call, Throughwire runs on private CN2 GIA premium routing with VLESS-Reality and Hysteria2, with no traffic, DNS or session logs and engineering-grade support. The trade-off is that it is not three dollars a month.