GUIDE

Clash iOS Setup Guide: Four Steps to Your First Configuration

Import subscription, pick mode, connect, verify—follow these four steps in order and you'll be done in about ten minutes. Each step spells out what to tap, what you should see, and what comes next. For deeper coverage of policy groups, DNS, TUN, and more, see the advanced handbook; this page sticks to the main path you can follow start to finish.

This guide follows the interface of Clash Plus on iOS. Desktop clients like Clash Verge Rev and FlClash use slightly different menu names—"Subscription" may appear as "Profiles," and "Proxy" may appear as "Proxies"—but the steps are identical, so you can follow along. If you haven't installed a client yet, head to the Download Center first.

STEP-00 Goal: client installed, subscription link in hand

Preparation: Install the Client, Get Your Subscription Link

You'll need two things before starting. First is the client itself: on iOS, Clash Plus is the top pick, installed via the App Store, requiring iOS 15.0 or later—see the iOS section of the Download Center. Once installed, the app icon appears on your home screen; no account registration is needed to open it the first time.

Second is a subscription link. It's an https URL provided by your proxy service in your account dashboard, which the client uses to download a configuration file containing nodes and routing rules. Copy it carefully from start to finish—a broken link or a stray trailing space will cause the download to fail. If your provider offers multiple formats, choose the one labeled "Clash."

With both in hand, you're ready for step one. No part of this process requires manually editing any files.

STEP-01 Goal: subscription entry appears in the config list and is enabled

Step One: Import Subscription

Open the client and find "Profiles" (some versions call it "Subscription") in the bottom tab bar. On first use this list is empty—tap the + button in the top-right corner and choose "Download from URL" from the popup menu. Paste your subscription link into the input field—if the link is already on your clipboard, most clients will prompt you to import it automatically, so tapping "Import" saves you the manual paste. You can leave the name field blank; the client will use the provider's name automatically. Confirm, then tap "Download."

The download usually finishes within seconds. On success, a new entry appears in the config list, showing the subscription name, node count, and update time. Tap the entry to set it as the active profile—once a checkmark appears next to it, switch to the "Proxies" tab, where you should see the policy groups and node list from the subscription. Seeing nodes confirms the import worked.

Two common issues: first, the download fails (timeout or 404)—check whether the link is complete with no extra spaces, and confirm your current network can reach the internet; second, the link isn't in Clash format, and the client will report a parsing failure—in that case you need to convert the subscription first, covered in the advanced handbook's multi-subscription and conversion chapter. As your provider updates nodes over time, pull to refresh on the config page or tap "Update" on the entry to fetch the latest content—no need to re-import.

STEP-02 Goal: mode set to Rule, nodes selected in policy groups

Step Two: Choose a Proxy Mode

Clash-family clients offer three running modes, switchable from the "Mode" setting on the home screen or in settings:

  • Rule mode: traffic is routed automatically based on the rules in your config—traffic that needs a proxy goes through a node, local traffic connects directly. This is the default choice for daily use.
  • Global mode: all traffic routes through the selected node, useful for briefly testing whether a node works, but not meant to stay on long-term.
  • Direct mode: all traffic bypasses every node, equivalent to a temporary bypass, used mainly for troubleshooting.

Once mode is set to "Rule," go to the "Proxies" tab. Nodes are grouped into cards by policy group; common group names include PROXY, Auto-Select, and region-based groups, with exact names depending on your subscription. Open the main policy group (usually the first in the list) and tap a node to select it; most clients include a lightning-bolt latency test button within each group—tap it to batch-test every node's response time, with lower numbers meaning faster response, and pick one showing green, low latency. If a group's type is "Auto-Select," the client picks the fastest node on its own, so no manual selection is needed.

How policy groups nest, the difference between url-test and fallback, and how to write your own routing rules are advanced topics covered in the policy groups and custom rules chapters of the advanced handbook. For your first setup, the steps above are all you need.

STEP-03 Goal: VPN badge appears in the status bar

Step Three: Connect

Return to the client's home screen and tap the most prominent main switch on the page. The first time you turn it on, iOS shows a system dialog along the lines of "'Clash Plus' Would Like to Add VPN Configurations"—this is the standard iOS authorization flow required of all proxy apps. Tap "Allow", then confirm with Face ID or your device passcode. You only need to authorize once; after that, the switch works instantly.

Once authorized, the switch turns on and a VPN badge appears in the status bar (or Control Center), confirming the system tunnel is up. You can check "Settings → General → VPN & Device Management" to see the VPN configuration the client created—this is expected and doesn't need any changes. If you accidentally tapped "Don't Allow" in the system dialog, the switch will bounce back off automatically; just turn it on again to repeat the authorization.

One iOS-specific note: the proxy runs inside the system's Network Extension process, which has a strict memory ceiling. If your subscription contains hundreds or thousands of nodes or an oversized rule set, the system may terminate the extension process, showing up as the connection dropping on its own. If this happens, switch to a subscription with fewer nodes, or trim your config following the "Rule-set subscriptions" approach in the advanced handbook. To disconnect during normal use, just turn off the main switch—there's no need to delete the VPN configuration from system settings.

STEP-04 Goal: confirm routing works as expected

Step Four: Verify It Works

With the connection active, go through this checklist:

  • The VPN badge is visible in the status bar or Control Center, and the switch on the client's home screen is on.
  • New entries keep appearing on the client's "Connections" or "Logs" page, confirming traffic is actually passing through the core.
  • A site that's normally unreachable without a proxy loads normally in your browser.
  • Any IP lookup page shows an exit region matching the node selected in your policy group.
  • In Rule mode, a frequently used local site loads at roughly the same speed as with the proxy off, confirming direct-connect rules are working.

If all five check out, your first setup is complete. If you get stuck on one: if every node times out, go back to step two, switch nodes, and refresh the subscription on the config page; if you're connected but routing is off (proxy traffic that should be direct, or vice versa), check whether mode is still stuck on Global, and whether your GeoIP database is outdated; if the logs show errors you don't recognize, work through them using the DNS and troubleshooting chapters in the advanced handbook. All of this goes beyond first-time setup—the handbook covers it in full.

NEXT

After Setup

From here, daily use comes down to two habits: refresh your subscription periodically, and re-test nodes on the Proxies page when things slow down. Want to go further—policy group types, TUN and Fake-IP, DNS tuning, merging multiple subscriptions—the advanced handbook covers each topic in full. Haven't installed a client yet? Start at the Download Center.