IPHONE · GETTING STARTED
Clash for iOS Setup and Connection
Follow these steps: import a subscription → choose a routing mode → connect → test. Get one configuration working first, then fine-tune it as needed.
Have your iPhone, an internet connection, and a subscription link or configuration file compatible with your chosen client ready. If you haven't installed the client yet, see the iOS download page.
Menu names may vary. The steps below refer to common iPhone client options such as “Configuration” or “Profiles,” “Routing Mode,” and “Connect.” Menus, permission prompts, and available settings differ between clients. If you don't see a button with the same name, look for the equivalent option to import a configuration or connect instead of relying on its position.
Configuration
Import a subscription
First, identify what you have. A subscription link is a URL provided by your configuration provider. The client uses it to retrieve and update a configuration. A local configuration is a file already saved on your device, and may have a separate import option. If you have a link, check that the provider says it works with your client or a compatible Clash configuration format. Don't use a regular webpage URL, account dashboard address, or a share link meant for another type of client as a configuration URL.
Copy the full subscription URL, open the client, and go to “Configuration,” “Profiles,” or a similarly named screen. Add a configuration, then look for an option such as “Download from URL” or “Import from link.” If you have a local file, choose file import instead. Paste the link into the URL field and check that the beginning and end are intact, with no added line breaks or spaces. Some clients ask for a name; use one that helps you tell configurations apart. There's no need to put the subscription URL in the name.
Tap Save or Download and wait for the client to retrieve and parse the configuration. A new entry should appear in the configuration list, but seeing it there doesn't necessarily mean it's active. Select it to make it the current configuration, then return to the main screen and confirm its name has changed. If the list contains older configurations, check which one is selected before proceeding. Some clients switch to the new configuration automatically; others require you to activate it separately. Use the active status shown on screen as your guide.
If you see a format error after pasting the link, check the provider's instructions and confirm the link matches the subscription type. If the download fails, first make sure the URL is reachable over a working network, then try again. Subscription URLs may contain access credentials, so don't post the full link in public forums, screenshots, or shared notes. If you're unsure how Profiles differ from subscriptions, see the glossary. For common import problems, follow the steps in the Help Center. Once the configuration is active, move on to routing mode settings.
How traffic is routed
Choose a routing mode
From the main screen, open “Routing Mode,” “Mode,” or a similarly named setting. The common options are Rule, Global, and Direct. For a first setup, choose Rule. The client checks each request against the rules in the current configuration, which determine whether it connects directly or uses a configured proxy. This setting controls how requests are handled; it doesn't create rules. If the configuration you imported doesn't include the rules you expect, switching to Rule mode won't add them.
Select “Rule,” return to the previous screen, and confirm that Rule is shown as the current mode. Then check whether the configuration has proxy outbounds available and select one if the provider's instructions require it. Depending on the client, proxy groups may appear under “Proxy,” “Policies,” or another menu. This is separate from the routing mode: the mode determines how requests are matched, while the proxy group determines which route is used for requests that match a proxy rule. Keep the provider's default group settings for now. Changing several things before your first connection can make problems harder to track down.
“Global” can help temporarily rule out issues with rule matching. It sends traffic the client can intercept through the selected proxy, so a successful test in Global mode doesn't prove that your rules are correct. “Direct” bypasses the proxy, which can be useful for comparison, but an enabled connection switch doesn't mean traffic is going through a proxy. When you're done testing, switch back to your usual mode.
If your client offers more options, start with these three basic meanings and check the client's documentation for details. Don't assume every app behaves identically just because modes have the same names. For more on rule order, proxy groups, and protocols, see the technical reference when you're ready to adjust your configuration. For now, note the selected mode and return to the main screen to connect.
System permissions
Connect
Before connecting, check two things on the main screen: the configuration you just imported is active, and the selected routing mode is the one you chose. Then turn on the “Connect” switch. iOS clients typically use a system VPN configuration to handle network requests from your device. The first time you connect, iOS may ask for permission to add a VPN configuration. Review the prompt, make sure the request comes from the client you're using, and follow the system instructions to allow it. If your device is protected by a passcode or biometric authentication, you may need to verify your identity.
After granting permission, return to the client and check that the connection switch stays on. Also check whether iOS shows a VPN status indicator. Its appearance can vary by iOS version, status bar space, or Control Center layout, so don't rely on a small icon alone. Check the connection status shown in the client as well. If the switch turns off by itself after you grant permission, don't keep tapping it rapidly. First check that the configuration can be read and that your device is online, then try connecting again.
If other apps on your device also use system VPN access, check whether they're connected. VPN connections can interfere with one another on iOS. Disconnect the previous client before switching to this one. Keep in mind that “connected” and “traffic is taking the expected route” are two different things. The first means the system connection is active; the second depends on your rules, proxy group, and the request itself, so you'll need to test it in the next step.
If regular webpages stop loading after you connect, turn off the connection and check that your Wi-Fi or cellular service works on its own. Then enable the current configuration again. This helps you separate a basic network issue from a configuration problem. Don't change DNS, mode, and configuration all at once before confirming that your network works; otherwise, it'll be hard to tell what affected the result. For permission prompts or a connection switch that won't stay on, see the Help Center. Once the switch stays on, test an actual request.
Test a request
Verify that it works
Leave the client connected and open a familiar page in Safari that should be affected by your current rules. Check that it loads, then return to the client and open its connection history or logs. Find the request you just made and check which rule matched and which outbound was used. The menu may be called “Connections,” “Active Connections,” or “Logs,” depending on the client. If the client doesn't show request details, at least compare the same page with the connection on and off. Don't judge by the color of the main-screen switch alone.
Choosing the right test target matters. A page that should connect directly can load successfully without proving that a proxy was used. A page that fails to load doesn't necessarily mean the system VPN permission is the problem. Recall whether you selected Rule, Global, or Direct in step two. In Rule mode, a request expected to connect directly should show a direct route. In Direct mode, a connected client doesn't mean the proxy is working. If the log doesn't match your expectations, check the active configuration, matched rule, and proxy group instead of reinstalling the client straight away.
To compare results, temporarily disconnect and revisit the same page on the same network, then reconnect and try again. Keep the test target and device network unchanged where possible. Switching from Wi-Fi to cellular or changes to the page itself can make results difficult to compare. If an app behaves differently from Safari, first check whether it's making requests the client can handle, then review the configuration rules. Don't judge a mode by how quickly a single page loads. The goal of this first setup is to confirm that the configuration, system connection, and request routing all work together.
After testing, note the name of the working configuration and the selected mode in your device notes for reference when you update the subscription. If only a few destinations behave unexpectedly, check the rules and logs first. If nothing loads, check your network, configuration, and system VPN status in that order. For a fuller troubleshooting guide, see the Help Center; for protocol and core differences, see the technical reference. For everyday use, keep the right configuration active, choose a mode that fits your needs, and verify results with a real request.