WLOC

Surge 5 · WLOC setup tutorial

Get WLOC running on Surge 5 — module, certificate, and MitM, step by step

Surge 5 is the smoothest setup of the six clients. WLOC outputs a native Surge module (wloc.sgmodule), you subscribe to it once, and Surge keeps it updated for you. The part people get wrong: they generate the CA inside Surge but never complete the iOS trust step. Surge will show MitM as active even without it. The indicator lies. Do not skip that step.

Before you start

  • WLOC installed.
  • Surge 5 installed (separate purchase — Surge 4 or earlier is not supported).
  • A test device.
  • Stable Wi-Fi.

Step 1: Subscribe to the WLOC module in Surge

Copy the Surge module URL: https://wloc.app/modules/wloc.sgmodule. In Surge, Module tab, tap +, paste as subscription. Surge fetches and activates. Make sure toggle is ON (green).

  • Three script hooks and MitM host list included — no manual editing.
  • As a subscription, Surge auto-updates. Pull manually via the refresh icon if needed.

Step 2: Configure MitM hostnames and generate the CA

Surge Settings → MitM → toggle ON. Under Hostname, add: gs-loc.apple.com and gs-loc-cn.apple.com. Tap Generate CA. Install the profile when iOS prompts.

  • Do not use * or leave empty — that decrypts all HTTPS traffic.
  • CA generation is one-time. Regenerate only if you remove the profile.

Step 3: Install and fully trust the CA certificate

Settings → General → VPN & Device Management → find Surge CA profile → Install → enter passcode. Then — do not skip — Settings → General → About → Certificate Trust Settings → toggle ON for Surge CA. Surge shows MitM as active even without iOS trust. The indicator lies. Certificate Trust Settings is the ground truth.

  • Step A: Settings → General → VPN & Device Management → Install profile.
  • Step B: Settings → General → About → Certificate Trust Settings → toggle ON.
  • Missing step B is the #1 cause of HTTPS not found.

Step 4: Verify with a test target

Save a low-risk public point in WLOC. Run diagnostics. Look for patch count > 0. Zero? Re-check CA trust first.

  • Patch count > 0 = WLOC working through Surge.
  • Surge activity log (clock icon) shows script requests hitting the WLOC Worker.

Step 5: Restore: clear, disable MitM, revoke CA

WLOC: clear target, confirm passthrough. Surge: turn OFF MitM. iOS: General → VPN & Device Management → remove Surge CA profile. About → Certificate Trust Settings → confirm gone.

  • Clear target first, then disable MitM, then remove profile.
  • Module subscription can remain — inert without active target and MitM.

Common gotchas

Module subscribed but not active

Check toggle is ON (green). Verify URL is exactly https://wloc.app/modules/wloc.sgmodule.

MitM ON but certificate not trusted

Surge shows MitM as active even without iOS trust. The indicator lies. Always verify in Certificate Trust Settings.

FAQ

Does the Surge module auto-update?

Yes. As a subscription, Surge periodically fetches the latest version. Manual refresh also available.

Can I use Surge for other VPN while WLOC is active?

Yes. The WLOC module only intercepts the two WPS hosts. Your other rules work independently.

WLOC

Setup complete? Verify every layer

Return to WLOC, run diagnostics, fix the first failed item, and verify normal location behavior after cleanup.