Skip to content

Crux for iOS

Crux for iOS is a post-quantum secure VPN client. It carries your traffic over the WireGuard protocol and layers Arqit's Symmetric Key Agreement (SKA) on top, so the keys protecting your tunnel are rotated continuously from a quantum-safe source rather than agreed once at connection time.

In day-to-day use it behaves like any other VPN app: you pick a tunnel and tap Connect. The work is in the one-time setup, which registers the device with the Arqit SKA-Platform that supplies the keys, and then loads the tunnel your administrator issued.

These guides walk through every screen in order. Nothing here requires prior VPN knowledge, but each step names the exact values your administrator needs to give you, so you can gather them in advance.

Before you start

Requirement Detail
iOS version iOS 18 or later
Devices iPhone and iPad
Permissions Camera, to scan tunnel QR codes
Network An internet connection that can reach your SKA-Platform
Account Credentials issued by your administrator — see below

What to ask your administrator for

Setup fails without these, so collect them before you begin.

For SKA-Platform registration

  • Username and password — your SKA-Platform account
  • Realm ID — the tenant your device belongs to
  • Domain and Region ID, but only if your deployment does not use the defaults (ska.quantum.cloud and ska)

For the tunnel itself

  • A WireGuard QR code, or a .conf configuration file, or the interface and peer values behind them

How setup works

The four stages of Crux for iOS setup: install from the App Store, register the device, add a tunnel, then connect.

Setup runs once. After that, Crux opens straight to the connect dial. Tap the diagram for a full-size view.

The app has four tabs — Home, Tunnels, Settings and About — and they are always available. What the Home tab shows, however, depends on how far through setup you are.

Decision chart showing what the Home tab displays depending on whether the device is registered and whether a tunnel is saved.

Home prompts you for whatever is still missing, and turns into the connect dial once the device is registered and at least one tunnel is saved. Tap the diagram for a full-size view.

The guides

For the change history of each release, see the iOS release notes.