Windows
Desktop users can choose from several graphical clients. Check your processor architecture and installer type first, then decide whether to enable launch at startup or system proxy settings.
Get the downloadFollow the steps from finding your device's client to verifying the connection: import a subscription, choose a rule mode, and review system settings.
Settings Overview
Common client settings each serve a different purpose. Select a setting on the left to see what it does, where to find it, and which config fields it relates to. New users can read through in order.
PROFILE · IMPORT FIRST
A subscription URL provides a configuration source; it does not establish a connection by itself. In the client's Configuration section, choose Download from URL, paste the address provided by your source, and wait for the import to finish. Then set that config as the current one. Check that proxy groups and rules appear after importing. If the lists are empty, verify the URL and format with your subscription provider instead of repeatedly toggling the connection. To keep work and personal settings separate, save distinct configs and switch between them as needed rather than mixing rules for different purposes in one file.
proxies:
proxy-groups:
rules:
Read next: Managing Multiple Profiles on iPhone
MODE · ROUTE TRAFFIC
For everyday use, start with Rule. The client checks requests against the rules in your config from top to bottom, then applies the matching traffic policy. Global sends all requests through the selected proxy; it can help you check whether a rule is affecting access. Direct sends requests without using a proxy. Changing modes does not edit your subscription or add missing proxy groups. If a site takes an unexpected route, check the current mode and rule matches before reinstalling the client—it usually makes the cause easier to find.
mode: rule
rules:
- MATCH,DIRECT
DNS · RESOLVE DOMAINS
DNS settings control how the client handles domain lookups. With Fake-IP, the core assigns a mapped address to a domain, then uses connection details to recover the domain and apply the matching rules. This is different from putting a real server address directly in the config. If a device that relies on LAN discovery or a particular app stops working, check whether its domain needs a filtering rule in your config. Save a copy of the original config before changing DNS, then adjust and test one setting at a time so you can identify what caused any change.
dns:
enable: true
enhanced-mode: fake-ip
How it works: Fake-IP and DNS Mapping
TUN · SYSTEM TRAFFIC
TUN mode controls how system traffic reaches the core. It is not a separate subscription and does not choose traffic rules for you. On iPhone, the client needs permission to create a system VPN connection; follow the prompts, then check for the VPN icon in the status bar. Return to the client and confirm the selected config, mode, and connection status. If the toggle immediately turns off, check system permission and make sure the config is valid. TUN labels and options vary between clients, so follow the settings in your installed version rather than copying steps from another platform.
tun:
enable: true
stack: system
Troubleshooting: Connection and Permission Issues
LAN · DEVICE ACCESS
Allow LAN Connections controls whether other devices on the same local network can access the proxy listener opened by the client. If you only use the client on your iPhone, you usually don't need to change this setting. To connect other devices on the network, also check the listener address, port, and system network permissions. Turning this on does not make the proxy automatically discoverable, and it does not enable proxy access through a mobile hotspot. When troubleshooting, first make sure the devices can reach each other on the network, then check the address and port—not just whether the connection toggle is on.
allow-lan: false
bind-address: "*"
Related terms: Listen Address and Port
Find a client
Start by identifying your device, then open the relevant platform page to check available clients, installation steps, and system requirements. Whether the same config works also depends on the config formats and core features supported by your chosen client.
Desktop users can choose from several graphical clients. Check your processor architecture and installer type first, then decide whether to enable launch at startup or system proxy settings.
Get the downloadCheck whether your Mac has Apple silicon or an Intel processor. During first launch, pay attention to system prompts for network extensions and permissions. Import your config after installation.
Get the downloadChoose an installer for your device's architecture. VPN permissions, background restrictions, and battery management settings can all affect whether a connection stays active.
Get the downloadFind the client for your iPhone or iPad through the relevant app store. After installation, import your config, grant system permission, and verify the connection in that order.
Get the downloadDesktop users can start with a graphical client package. For servers and routers, check the architecture, core binary, and how the software is run.
Get the downloadComparing clients on the same platform? Browse all clients → The downloads page lists platform links and compatibility notes in one place.
Quick Start
This is a preview of the setup sequence. Each step has a clear completion check. If something goes wrong, revisit the last completed step; that usually works better than changing several settings at once.
Open the download page for your device and install the client by following the system prompts. Once you have your subscription URL, find Configuration or Download from URL in the client, paste the address, and import it. Make sure the config appears in the list, then set it as the current one. Copying a URL to the clipboard alone does not import it into the client. If your provider gives you a local YAML file, use the file import option and make sure its indentation stays intact.
After importing, check for available proxy groups and select one provided by your config. Then set the traffic mode to Rule. In Rule mode, requests follow the match order in your config, from top to bottom. To diagnose how a specific site is routed, briefly compare Global and Direct, then switch back to your usual mode when you're done. Modes and proxy groups serve different purposes, so changing one does not mean the other is configured.
Turn on the connection toggle and allow the VPN configuration when prompted by iOS. Return to the client and confirm the toggle is still on. Test a site or app you actually need, then check the connection logs to see whether its requests matched the expected rules. If no connection is established, check permissions and the current config first. If the connection is active but one app behaves differently, check the mode, rules, and DNS. Verifying that the toggle is on and that the destination works as separate checks helps narrow down the issue.
Read the full setup guide → for screen-by-screen instructions, checks, and common sticking points.
Open-source ecosystem
Clash first drew attention as a rule-based proxy core. Since then, the community has developed core forks and graphical clients for different systems, so “Clash client” no longer refers to a single app. The original Clash, Clash Meta, and mihomo differ in maintenance status, features, and config support. Before downloading, check the client name and read about the core it uses. A feature supported by one core is not necessarily available in every client.
Open-source repositories provide code you can read, issue histories, and release notes. For example, mihomo's config docs explain what its fields mean; graphical clients import configs, display proxy groups, and run the core they bundle. This site offers practical notes in Chinese, but it does not replace project-specific release documentation. Repository commands are useful if you want to browse source code or track changes. If you just want to install a client on your phone, use the platform links above.
The core handles rule matching, DNS, and traffic forwarding; the client provides the system interface and controls. Projects with similar names may use different core builds, defaults, and release schedules. Before editing YAML based on a guide, confirm that its fields apply to the core you're using. If a field isn't recognized, check the relevant project's docs instead of inferring config syntax from a toggle's label in the app.
Config sources, clients, and cores can all be updated separately. A subscription update usually refreshes config content; it does not replace the client. An app update also doesn't guarantee that every custom field in an older config will keep working the same way. Keep a working copy before making changes, then check the import, proxy groups, and real-world access after updating. If you use the same subscription across devices, confirm that each platform's client supports the relevant protocols and fields rather than assuming one change will behave identically everywhere.
Reading list
From beginner questions to DNS behavior, these articles each cover a common scenario. Start with the one closest to your issue, then return to the client to make changes. This can save time compared with trying settings at random across multiple screens.
Compare how Fake-IP and redir-host work, learn what mapped addresses are for, and find out when LAN devices and some apps may need filtering rules.
Read article → Quick AnswersFind common sticking points with installation, imports, permissions, and mode selection. Each answer starts with where to check, then explains what to do next.
Read article → Getting StartedLearn the difference between Profiles, subscriptions, and local configs, and how to add, update, and switch configs for different uses.
Read article →Have a quick question? Visit the Help Center. Need to understand a config field? Open the Glossary. Browse all articles →