How Many Devices a VPN Covers: Counting Connections, Not Gadgets
The number in a provider’s device limit is a cap on simultaneous connections, not on how many machines you may install the software on. That distinction decides everything about planning coverage: a router counts as one connection no matter how many things sit behind it, a laptop tunnelled twice counts twice, and a session that did not close cleanly can hold a slot while you are not using anything. Treat this as a design question about your household rather than a number to compare between products.
A device, in this context, is a connection
You can generally install a client on everything you own. What is metered is how many tunnels are established at the same moment. So the arithmetic is about simultaneity, not inventory: the phone in your pocket and the laptop asleep in a bag are not the same load, and a household of a dozen devices may only ever have three tunnels up at once.
This is why the honest question is not “how many devices do I have” but “how many of them are awake, on a network, and tunnelling at the same time”. Answer that and the limit stops being an abstract feature and becomes a fact about your week.
The router changes the arithmetic completely
A tunnel on your router is one connection, covering an unlimited number of devices behind it. From the service’s point of view there is a single client dialling in; the fifteen things on your network are invisible to it. That is the single largest lever anyone has over this number, and it is the reason device limits matter much less to households that put the tunnel at the edge.
It comes with everything else that arrangement brings, which is a longer list than the connection count suggests — see what a router tunnel commits you to. But if the constraint you are trying to solve is genuinely the number of simultaneous connections, this is the answer, and no plan comparison will beat it.
What sharing one exit address costs
Coverage is not free of side effects, and this is the interesting one. Every device using the same tunnel presents the same address to the internet. The more devices you put behind it, the more activity is attributed to that one address, and the more the internet’s automated defences treat your household as a single busy actor.
The visible symptoms are familiar: challenge prompts on sites that never used to ask, rate limits reached faster than they should be, and services that behave as though you are somebody suspicious. One device downloading heavily changes the experience of everyone else, because they are all the same address as far as anything outside is concerned. The dynamics of shared and dedicated exit addresses apply here at family scale rather than provider scale.
There is a diagnostic cost too. When something outside reacts badly to your address, you cannot tell which device caused it, because there is no per-device information left to look at.
Where the count goes wrong
Five ways people end up using more slots than they think.
Double coverage. A client running on a device that already sits behind a router tunnel consumes a second connection, encrypts everything twice, adds a hop, and makes routing hard to reason about. If you run both layers, exclude the devices with their own client from the router’s tunnel wherever the firmware allows it.
Sessions that did not close. An ungraceful disconnect — a laptop lid closed, a phone that lost signal mid-handshake — can leave the far end believing a connection is still open. It usually times out. It sometimes times out later than you would like, and the slot is unavailable in the meantime.
A device with two configurations. Two clients or two profiles on the same machine, one of them started automatically, is a common way to spend a slot on something nobody is using.
Devices that reconnect on their own. Always-on settings and reconnect-on-demand facilities are doing their job when they bring a tunnel back overnight, and they hold slots when you assumed nothing was connected. That is a feature working, not a fault, but it belongs in the count.
Everyone else in the house. Guests, family members, and the phones of people visiting for the weekend all draw on the same allowance if they are using your subscription.
Plan coverage by what needs it, not by what you own
Three questions sort every device you have.
Which devices leave the building? Those need their own client, because a router at home cannot reach a laptop on somebody else’s Wi-Fi or a phone on cellular. These are the slots you genuinely cannot avoid spending.
Which devices never leave? A desktop, a console, a network drive. The router covers them for the price of the one connection it was already using.
Which devices cannot run anything at all? Televisions, most appliances, anything with a curated app catalogue and no client for it. The router is the only option, and covering them is usually the reason people set it up in the first place — the trade-offs, feature by feature, are laid out in why a router VPN behaves differently from a VPN app.
Do that sort once and the answer falls out. In most arrangements it produces a handful of individual connections plus one at the edge — a much smaller number than the device count, and a much easier requirement to satisfy.
What “unlimited” means, and where the real limit moves
An unlimited-connection offer means unlimited simultaneous tunnels. It is a genuine convenience and it does not remove a limit so much as relocate it.
The limits that remain are physical and practical. A router’s processor caps what a network-edge tunnel can carry, no matter how many devices are permitted. An exit address shared by more devices accumulates more reputation problems. And every additional tunnel is one more thing whose failure you would have to notice — which, on a household where several devices fail open silently, is the constraint that actually bites. If you are still deciding the shape of the arrangement, which layer carries the tunnel is the decision that sets this number, rather than the other way round.