What happens when you connect
The user flow is intentionally simple: open the app and tap Connect. Behind that button, SanazNet checks the account, chooses a route, authorizes one access period and synchronizes the selected server.
- 1
Check account and plan state
The server first evaluates whether the device is Guest, registered or Premium and whether email, identity, device-limit and access-allowance rules permit a new period. The server is authoritative; the client displays the result.
- 2
Choose Auto or a manual server
In Auto mode, SanazNet considers only ready nodes and ranks them using live node health, capacity and connection quality. When manual selection is enabled by policy, the user can choose an available node directly.
- 3
Authorize the access period
Premium proceeds directly to connection authorization. On Free, when the active policy requires a sponsored step, that same session receives a reward challenge. Completion or fallback applies only to that session and does not create a second access period.
- 4
Publish a bounded access lease
After authorization, the control plane publishes a bounded lease for that device, node and access period. The VPN node must apply the latest authorization generation; possessing the app, profile or credential alone is not an access grant.
- 5
Establish IKEv2
Supported clients use IKEv2 for the secure tunnel. The operating system may request VPN permission or installation of a required component. The client then keeps tunnel state and usage aligned with server-side session state.
- 6
Disconnect, reconnect and expiry
Manual disconnect pauses or ends access according to the platform flow. While the same access period is still valid, reconnect should not consume another reward or allowance unnecessarily. When the period deadline or limit is reached, that access period closes.