SETUP GUIDE · Documentation

Clash Subscription Setup Guide

The complete process from installing a client to verifying the proxy works: import the subscription, choose a proxy mode, enable system proxy, and verify the connection. Four main steps plus one preparation step, about 10 minutes total, for Windows, macOS, Android, and iOS.

About 10 minutesCore: mihomoUpdated Jul 24, 2026

Client interfaces differ, but the process is the same

Clients such as Clash Plus, Clash Verge Rev, ClashX Meta, and Clash Meta for Android place and name their buttons slightly differently, but the core process never changes: get the subscription link → import the profile → pick a mode and node → enable system proxy → verify. This guide gives exact click paths per platform; if you can't find a matching button, look under the four entry points labeled Profiles, Subscription, Proxies, and Settings in your client. On iOS, install Clash Plus from the App Store; official site: clashplus.io.

Step 1: Prepare a Client and a Subscription Link

Before you start, have two things ready: an installed client and a working subscription link. You can't proceed without either, so sort them out in this step first.

Pick one client for your platform; the download page has the full list for every platform with system requirements and version notes: on Windows, Clash Plus or Clash Verge Rev is recommended; on macOS, use Clash Plus or ClashX Meta; on Android, use Clash Plus or Clash Meta for Android; on iOS, install Clash Plus directly from the App Store. Installation itself has no special steps—just follow the system prompts. If you hit permission, blocking, or port-conflict issues during installation on Windows, the troubleshooting page covers the fixes.

A subscription link is a URL starting with https:// provided by your service provider. Node information and routing rules are packed into it, and once the client has the link it pulls the entire configuration automatically—no manual server addresses needed. You'll usually find it in your provider's user center behind buttons like "Copy Subscription URL" or "Copy Clash Subscription". Make sure to copy the Clash / Clash Meta universal format, not a format specific to another client; the wrong format will fail to parse on import.

A subscription link is as sensitive as your account credentials

Anyone who has the link can use your nodes. Never paste it into public groups, forums, or screenshots. If it has already leaked, reset the subscription URL in your provider's dashboard and re-import with the new link.

Step 2: Import the Subscription

On Windows, using Clash Verge Rev as the example: open the main window, click "Subscription" in the left sidebar to open the subscription manager, paste the link into the input box at the top, and click "Import". A new profile card appears in the list showing the profile name and update time; click the card to set it as the active profile, and an "In Use" badge appears on it—this step is done. The Clash Plus desktop client is even more direct: the home page has a subscription input box, and pasting the link imports and activates it in one click.

On macOS, using ClashX Meta as the example: click the cat icon in the menu bar, go to "Config → Remote Config → Manage", click "Add" in the window that opens, paste the link into the Url field and give it a name, confirm, wait for the profile to appear in the list, then go back to the menu bar's "Config" submenu and check it.

Android and iOS follow the same idea: on the app's "Profiles" or "Subscription" page, tap the plus button, choose URL as the type, paste the link, and save, then go back to the list and select the profile you just imported. Some providers also offer a subscription QR code in their dashboard, so mobile users can scan to import and skip copy-pasting.

Signs of a successful import: the proxy page loads a node list, and the profile card shows a recent update time. If the import reports a parse failure or an invalid profile, go back to your provider's dashboard and confirm you copied the Clash universal format. A subscription is not one-and-done—nodes are added and removed as the provider adjusts, so click the "Update" button on the profile every few days. Most clients also support an auto-update interval, which you can find on the profile entry or in settings. Update failures usually show up as timeouts or returned errors; common causes and a sensible auto-update interval are covered on the troubleshooting page and won't be expanded here.

Step 3: Choose a Proxy Mode and Node

After importing the profile, don't rush to connect—confirm two things first: the proxy mode and the node. Together they decide how your traffic flows. Clash has three outbound modes, each with its own traffic behavior:

ModeTraffic BehaviorBest For
RuleRouting rules decide whether traffic goes through the proxy or directDefault for daily use; automatic split between mainland China and overseas traffic
GlobalAll traffic goes through the selected nodeDebugging routing issues or temporary full-proxy sessions
DirectAll traffic bypasses nodes and connects directlyPausing the proxy without quitting the client

Use rule mode day to day: sites in mainland China connect directly while traffic outside China goes through a node, giving the best balance of speed and experience. Global mode sends all traffic through the selected node; turn it on temporarily only when debugging routing issues or using services that must be fully proxied. Direct mode lets all traffic bypass the nodes—effectively pausing the proxy without quitting the client.

Where to switch: in Clash Verge Rev, at the top of the "Proxies" page; in ClashX Meta, in the menu bar's "Outbound Mode" submenu; in Clash Meta for Android, on the mode tabs of the main screen; in Clash Plus, front and center on the home page of every platform.

Nodes are selected on the "Proxies" page. A profile usually contains several proxy groups, most commonly ones like "Node Select" and "Auto Select": auto-select (url-test) picks a node by latency automatically, while a manual group lets you choose after expanding it. Before choosing, click the speed-test button next to the group to run a latency test, wait for the numbers to load, and pick a node with low, stable latency. Latency is only a reference—during evening peak hours, judge by how fast pages actually load. The differences between proxy group types and finer routing tricks are advanced topics, with a dedicated chapter on the advanced configuration page. At the tutorial stage, one combo is enough: rule mode + auto-select.

Step 4: Enable System Proxy and Connect

The key switch on Windows desktop clients is called "System Proxy". Clash Verge Rev has a "System Proxy" toggle on the main window or in settings; once enabled, the system proxy points to the client's local listen address, and traffic from browsers and most desktop apps flows into Clash's routing. If you want it always on, also enable "Launch at Login" so you don't have to click it again after a reboot.

On macOS, ClashX Meta has a "Set as system proxy" checkbox in the menu bar; the Clash Plus desktop client puts the master switch on its home page. Once checked, the HTTP and SOCKS proxy addresses are written automatically into the system's "Network → Proxies" settings—no manual entry needed.

Android and iOS have no "system proxy" concept; they take over traffic via VPN: in Clash Meta for Android, tap start on the main screen and tap "Allow" when the system shows the VPN connection request; Clash Plus on iOS likewise asks to add a VPN configuration the first time you flip the switch—once allowed, a VPN badge in the status bar means traffic is captured. Battery use and background keep-alive on mobile are covered in a separate article and won't be expanded in this tutorial.

On desktop, to route apps that don't follow the system proxy (some command-line tools, dev tools, game platforms) through Clash, manually enter the client's local listen address 127.0.0.1 plus the port in the app. Common default ports are listed below; the actual values shown on the client's "Settings" page take precedence:

ClientMixed Port (HTTP/SOCKS)External Controller Port
Clash Verge Rev78979097
Clash for Windows78909090
ClashX Meta78909090

When the port is taken by another program, the client fails to start or throws a listen error—just switch to a free port; detailed handling is on the troubleshooting page. TUN mode can capture all traffic including command-line tools, but it involves a virtual network adapter and permission setup; the advanced configuration page has a full chapter on it. At the beginner stage, system proxy is enough.

Step 5: Verify the Proxy Works

Spending a minute verifying after connecting is far easier than troubleshooting after something goes wrong.

The browser method: open an IP lookup site like ip.sb and check the exit IP and its location shown on the page. In rule mode, visiting a lookup site outside China should show the region where your node is located; if it still shows your local ISP's IP, your traffic is not going through the proxy.

The command-line method is more direct—replace the port with the actual value from the previous step:

curl -x http://127.0.0.1:7897 https://api.ip.sb/ip

If the returned IP matches the node's region, the proxy chain is working. For a control group, run it again without the -x flag—the two results should differ.

If verification fails, check in this order: whether the system proxy switch is on; whether the browser has an extension that takes over proxying—disable it and retest; whether the port in your command matches the client's settings page; switch to global mode and retest—if global works but rule mode doesn't, the problem is the routing rules, not the node; Windows Store (UWP) apps have loopback restrictions and need a separate exemption. Detailed fixes for each item are collected on the troubleshooting page—look them up by symptom. At this point, everyday setup is complete.

Advanced Topics & Help NEXT · 3 Links

Advanced Configuration Handbook

Proxy groups in practice, subscription-based rule-set management, DNS optimization, TUN and Fake-IP, and merging multiple subscriptions—one systematic long-form guide.

Go to Advanced Setup

Troubleshooting

High-frequency issues like subscription update failures, port conflicts, DNS leaks, and UWP loopback restrictions, organized by category for step-by-step diagnosis.

View Common Issues

Client Downloads

Client lists for five platforms with system requirements and version notes—start here when switching clients or setting up a second device.

Go to Downloads