Surge 5 · WLOC setup tutorial
Get WLOC running on Surge 5 — module, certificate, and MitM, step by step
Surge 5 is the smoothest setup of the six clients. WLOC outputs a native Surge module (wloc.sgmodule), you subscribe to it once, and Surge keeps it updated for you. The part people get wrong: they generate the CA inside Surge but never complete the iOS trust step. Surge will show MitM as active even without it. The indicator lies. Do not skip that step.
Before you start
- WLOC installed.
- Surge 5 installed (separate purchase — Surge 4 or earlier is not supported).
- A test device.
- Stable Wi-Fi.
Step 1: Subscribe to the WLOC module in Surge
Copy the Surge module URL: https://wloc.app/modules/wloc.sgmodule. In Surge, Module tab, tap +, paste as subscription. Surge fetches and activates. Make sure toggle is ON (green).
- Three script hooks and MitM host list included — no manual editing.
- As a subscription, Surge auto-updates. Pull manually via the refresh icon if needed.
Step 2: Configure MitM hostnames and generate the CA
Surge Settings → MitM → toggle ON. Under Hostname, add: gs-loc.apple.com and gs-loc-cn.apple.com. Tap Generate CA. Install the profile when iOS prompts.
- Do not use * or leave empty — that decrypts all HTTPS traffic.
- CA generation is one-time. Regenerate only if you remove the profile.
Step 3: Install and fully trust the CA certificate
Settings → General → VPN & Device Management → find Surge CA profile → Install → enter passcode. Then — do not skip — Settings → General → About → Certificate Trust Settings → toggle ON for Surge CA. Surge shows MitM as active even without iOS trust. The indicator lies. Certificate Trust Settings is the ground truth.
- Step A: Settings → General → VPN & Device Management → Install profile.
- Step B: Settings → General → About → Certificate Trust Settings → toggle ON.
- Missing step B is the #1 cause of HTTPS not found.
Step 4: Verify with a test target
Save a low-risk public point in WLOC. Run diagnostics. Look for patch count > 0. Zero? Re-check CA trust first.
- Patch count > 0 = WLOC working through Surge.
- Surge activity log (clock icon) shows script requests hitting the WLOC Worker.
Step 5: Restore: clear, disable MitM, revoke CA
WLOC: clear target, confirm passthrough. Surge: turn OFF MitM. iOS: General → VPN & Device Management → remove Surge CA profile. About → Certificate Trust Settings → confirm gone.
- Clear target first, then disable MitM, then remove profile.
- Module subscription can remain — inert without active target and MitM.
Common gotchas
Module subscribed but not active
Check toggle is ON (green). Verify URL is exactly https://wloc.app/modules/wloc.sgmodule.
MitM ON but certificate not trusted
Surge shows MitM as active even without iOS trust. The indicator lies. Always verify in Certificate Trust Settings.
FAQ
Does the Surge module auto-update?
Yes. As a subscription, Surge periodically fetches the latest version. Manual refresh also available.
Can I use Surge for other VPN while WLOC is active?
Yes. The WLOC module only intercepts the two WPS hosts. Your other rules work independently.