10 Minute Setup

Clash for iOS Tutorial

Complete the basic setup in four steps: import a subscription, choose a mode, connect the system VPN, and verify the results. The process focuses on iPhone and iPad, but the same sequence works with other Clash clients.

Basic Setup Path About 10 minutes
  1. 01
    Import Subscription Get a usable profile
  2. 02
    Choose a Mode Set traffic routing
  3. 03
    Establish Connection Authorize the system VPN
  4. 04
    Verify Results Check rule matches

Interface Notes

Confirm Your Platform First

Button names and menu locations vary slightly between clients, but the setup order is the same. Read the guidance for your device first, then continue with the steps below.

iOS Network Extension Interface

On iPhone and iPad, configuration, proxy, logs, and the connection switch are usually located in separate sections. The first time you connect, iOS displays a confirmation dialog to add a VPN configuration. Use your device passcode, Touch ID, or Face ID to authorize it. This is normally a one-time step; afterward, you can connect directly from the client.

Preparation 2 minutes

Before You Start

Before you begin, install a Clash client and obtain a subscription URL that is still valid. Subscription URLs are usually generated by your network service provider; they are not ordinary website homepages or individual node names. You can typically copy the correct URL from the provider’s subscription page, and the client should be able to read it directly as a configuration file. If the client is not installed yet, visit the iOS download page to choose a version for iPhone or iPad.

When copying a subscription URL, use the page’s Copy button whenever possible instead of selecting text manually. Uppercase and lowercase letters, symbols, and parameters all matter; omitting one character can make the download fail. Treat subscriptions as personal configuration data and do not post them in public comments, screenshots, or group chats. Keep the provider’s page open until the client successfully reads the profile, so you can quickly check for expiration or permission messages.

Make sure the device can currently access the internet. Temporarily turn off the client connection and use Safari to open a website you normally visit. If the underlying network is unavailable, subscription downloads and later verification will fail; resolve Wi-Fi, cellular data, or local network sign-in issues first. Corporate, campus, and hotel networks may require browser authentication before access is granted. Continue only after ordinary webpages load normally.

Step 1 Import Subscription

Import the Subscription and Enable the Profile

Open the Clash client and go to the “Configuration,” “Subscription,” or “Profiles” page. Find the Add button, usually in the upper-right corner, and choose import by URL, remote configuration, or subscription URL. Paste the complete address you copied earlier. You can enter a short, recognizable name, such as the provider name or intended use; this name only affects the local list and does not change the subscription content.

After confirmation, the client requests the subscription URL and parses the returned configuration. Normally, a new entry appears in the configuration list within a few seconds, often with an update time or update action. Select the entry so it becomes the active profile. Saving a subscription to the list does not mean it is in use; if sample or older profiles remain, explicitly select the newly imported one.

If the page reports a format error, parsing failure, or empty configuration, do not keep tapping Connect. Return to the subscription field and check for spaces before or after the URL. Make sure you copied a Clash or generic subscription URL—not a QR image URL, web share page, or client-specific redirect link. You can also try one update while the network is working normally. If the provider offers multiple formats, choose the entry labeled Clash, Mihomo, or YAML.

After the profile appears successfully, open its details or preview and confirm that it contains structures such as “Proxies,” “Proxy Groups,” and “Rules.” There is no need to edit individual fields; simply verify that parsing errors are no longer shown. Then return to the home or proxy page to choose an operating mode. For relationships among fields such as proxies, proxy-groups, and rules, see the proxy node field reference when you need to maintain a configuration manually.

Before Moving On, You Should See

  • The newly added subscription appears in the configuration list.
  • The new profile is selected or enabled.
  • The profile details identify proxies, proxy groups, and rules.
  • No parsing error remains after the update completes.
Step 2 Choose a Mode

Choose Rule Mode and a Policy Group

Once the profile is enabled, open the client’s “Proxy,” “Mode,” or “Proxies” page. Common Clash operating modes include rule mode, global mode, and direct mode. For a first setup, rule mode is recommended. In this mode, the configuration rules decide whether each connection goes direct, uses a proxy, or is rejected, allowing everyday sites and proxy-required destinations to take different paths.

Global mode sends most connections through the currently selected proxy policy. It can help briefly determine whether a proxy works, but it should not be treated as the default conclusion for a first setup. Direct mode bypasses the proxy and is mainly useful for comparison tests or temporary bypassing. If the page already shows “Rule,” leave it unchanged. If it shows “Global” or “Direct,” open the mode selector and switch to rule mode.

Next, review the policy groups. A subscription often provides one or more groups, such as node selection, automatic selection, failover, or purpose-based groups. Open the primary proxy selection group and choose an explicitly usable policy. If both automatic selection and individual nodes are available, start with the provider’s recommended automatic policy. If it returns no result, manually select a node for the initial test.

Do not judge whether setup is complete from the node list alone. Policy groups are often nested: a top-level group may reference another automatic selection group, while the rules ultimately point to the top-level group. Confirm that the primary group shows a current choice rather than blank, unselected, or error status. If the client offers a group test button, you may run it once, but its result only assists selection and cannot replace the webpage test later.

There is no need to read every rule at this stage, and you should not reorder rules just to obtain a particular displayed result. Rules are matched from top to bottom, and matching stops at the first hit; changing one line can alter the routing of many websites. If you need domain routing, application rules, or local network exceptions, finish this tutorial first, then make targeted changes and test them individually using the rule syntax guide.

Step 3 System Connection

Turn On the Connection and Allow the VPN Profile

Return to the client home screen and find the connection switch. It is usually at the top of the page, in the status area, or in the center of a dashboard. After you tap it, iOS displays a system prompt the first time, asking whether to allow a VPN configuration to be added. Choose Allow, then use your device passcode, Touch ID, or Face ID to confirm. iOS handles this step; the client can create a network extension connection only after authorization is granted.

After authorization, stay in the client briefly. Wait for the status to change from Starting to Connected, or confirm that the switch remains on. iPhone and iPad may show a VPN indicator in the top status area, but its location varies by device and iOS version. Use the client’s connection status as the primary indicator. If the switch turns off immediately, the connection was not established; check the client’s error message or the end of its log.

The first connection may take a few seconds to load the profile, initialize DNS, and create the network extension. Repeatedly toggling the switch can interrupt this process. Wait about ten seconds before testing in a browser. If another VPN profile is saved in system settings, make sure the Clash profile is the active one. iOS usually maintains only one primary VPN connection at a time, and another VPN app may replace the current state.

If iOS does not show an authorization prompt and the connection never starts, open Settings and check the VPN-related page for a profile belonging to the client. Previously authorized devices do not ask every time. If the profile exists but its status is abnormal, return to Clash, turn off the connection, wait a few seconds, and turn it on again. If it still fails, restart the client before deleting the subscription. Deleting the subscription will not fix a system authorization issue and only adds setup work.

Once the connection is stable, keep the app in the foreground for the first verification. After browser access and rule matches work normally, decide whether to enable on-demand connections, automatic cellular connections, or background updates. On-demand connections can start the VPN automatically based on network conditions and are best enabled after stability is confirmed. Manual control is easier to understand during initial setup.

Direct Signs of a Successful Connection

  • The client’s connection switch stays on instead of immediately reverting.
  • The status area shows Connected or Running.
  • System settings show the VPN pointing to the Clash client in use.
  • The log does not repeatedly show the same startup error.
Step 4 Verify Results

Verify Network Access and Rule Matching

After connecting, use Safari to open a website that normally works directly, then visit a destination expected to use the proxy. This tests both direct and proxied paths. Testing only one site cannot immediately distinguish a site outage from a DNS issue, node problem, or rule mismatch. Use a new private tab or refresh the page to reduce the effect of browser cache.

Then return to the client and open its connection records, logs, or sessions page. Find the domain you just visited and check which rule matched and which policy was ultimately used. A direct site usually shows DIRECT or a direct policy; a destination requiring the proxy should show the primary proxy group or current node. When the page result matches the recorded route, the subscription, mode, policy group, and system connection are working as one complete chain.

If a webpage opens but takes an unexpected route, do not switch clients immediately. Confirm that rule mode is still active, then check the rule matching the destination domain. A common cause is that an earlier rule matched first, or the primary policy group switched to direct. When the log shows a rule name, inspect the path in this order: domain, rule, policy group, node. This is faster than changing DNS blindly.

You can also compare the connection switch states: turn off Clash and reload the same page, record the result, then turn the connection back on and reload it again. The difference helps confirm whether traffic is actually passing through the client. Do not switch Wi-Fi, cellular data, and nodes during the comparison, or you will introduce multiple variables. Change one condition at a time so the result remains meaningful.

After verification, enable automatic subscription updates if needed. Avoid setting an overly frequent interval; normal use should follow the provider’s recommendation. Updated profiles may change policy groups and rules, so if behavior changes after an update, first check the profile update time and current policy selection. For long-term custom rules, use overrides or merging to prevent subscription updates from overwriting manual changes. See the override and merge reference for the structure.

Troubleshooting Follow the Order

Quick Troubleshooting When the Connection Fails

If internet access still fails after the four steps, do not change several options at once. Check basic connectivity, the subscription, policies, the connection, and DNS in that order, retesting after each item. The order matters: changing local DNS cannot fix an invalid upstream subscription, and switching nodes cannot produce traffic if the system connection was never established.

Subscription Update Failed

Turn off the client connection, confirm in a browser that the current network can open ordinary webpages, and then manually update from the configuration page. Check that the subscription URL is complete, has not expired, and does not need to be regenerated by the provider. An old profile that still displays correctly does not mean the local configuration is damaged; the subscription source may simply be temporarily unreachable. Keep the old profile until the new URL is confirmed, then replace it.

Connected but Websites Won’t Open

Confirm that the primary policy group is not blank and that you did not accidentally choose a direct or reject policy. Then switch to another usable node in the same group and test the same website. If all nodes behave the same way, check the connection record for DNS resolution failures. Do not enable DNS hijacking, change nameservers, and switch enhanced modes without evidence from the logs. These settings depend on the network environment; see the DNS configuration section for the relevant fields.

Some Websites Work, Others Fail

This usually means the system connection is established and the issue is more likely related to rule matching, the destination site, or the current node. Open the connection records and compare the policies used by successful and failed sites. If the failed destination was routed direct even though it should use the proxy, check rule order. If it already uses the proxy, test another node in the same group. Investigate DNS only when similar domains consistently fail to resolve.

The Connection Switch Turns Off

Start with the client’s last clear error instead of treating every log entry as a fault. Common causes include an unloadable profile, another app replacing the system VPN, an abnormal network extension state, or fields unsupported by the client. Re-select the newly imported profile and try starting it once. If the issue began after manual editing, compare it with the original subscription profile. Once the original works, add custom content back section by section.

The Connection Fails After Changing Networks

When switching from Wi-Fi to cellular data, or joining a public network that requires browser sign-in, an existing connection may need to be re-established. Turn off Clash, complete the public network authentication, and turn the connection back on. If the problem occurs only on one Wi-Fi network, check for special DNS, a local proxy, or access restrictions instead of assuming the subscription has failed. Testing different networks with the same node and mode helps separate local network issues from configuration issues.

Configuration Reference

Need to Modify the Configuration Further

After the basic connection works, use the configuration reference to find sections on DNS, rule syntax, policy groups, node fields, or override and merge behavior. This tutorial keeps the operational path focused; field-level details are collected on the reference page.

Open Configuration Reference

Setup Complete

Basic Setup Complete

Keep the current working profile as a baseline. When changing nodes, updating the subscription, or editing rules later, change one item at a time and confirm the result in the connection records.