From installing a client and importing a subscription to setting up rule-based routing and system-wide TUN mode, this page covers Clash on every platform. It walks through popular clients like Clash Verge Rev and FlClash plus the Mihomo core, for beginners and advanced users alike.
Whether you use Windows, macOS, Android or Linux, these 5 steps get you installed, configured and connected.
1
Download a client
Clash Verge Rev for Windows / macOS / Linux, FlClash for Android
2
Install and launch
Run the installer; the Clash icon appears in the tray or notification bar
3
Import your subscription
Open the Profiles page, paste your subscription URL and import it
4
Pick a proxy node
Run a latency test in the proxy panel and pick a node under 200 ms
5
Turn on the system proxy
Enable the System Proxy switch and your browser goes through Clash
Need games or desktop apps to use the proxy too? The system proxy only works for apps that respect proxy settings, such as browsers. To route all traffic through Clash, also enable TUN mode. See Advanced features.
Platform guides
How to install Clash on each platform
Pick your operating system to see the install steps and recommended client.
Clash Verge Rev · Installing on Windows
1
Download the installer
Download the Clash Verge Rev Windows x64 installer (.exe). On Windows on ARM devices with Qualcomm Snapdragon chips, choose the ARM64 build.
2
Run the installer
Double-click the .exe file. If Windows SmartScreen appears, click More info → Run anyway, then follow the setup wizard.
3
Install Service Mode (recommended)
After the first launch, go to Settings → System Settings → Service Mode and click Install (admin rights required). This unlocks system-wide TUN mode.
Service Mode is a built-in feature of the client. A UAC admin prompt during install is expected; just click Yes.
4
Import your subscription URL
Click Profiles in the sidebar → + in the top right → paste your subscription URL → Import. Your node list appears shortly.
5
Pick a node and enable the proxy
Go to the Proxies page, run a latency test in a proxy group and pick a low-latency node. Then turn on System Proxy.
Clash Verge Rev · Installing on macOS
1
Check your Mac's chip
Open the Apple menu → About This Mac. Apple M-series chips need the aarch64 / arm64 build; Intel processors need the x64 build.
2
Download and install the DMG
Download the .dmg file, open it, and drag the Clash Verge Rev icon into the Applications folder.
3
Get past Gatekeeper
On first launch, right-click the app icon → choose Open → click Open again in the dialog.
On macOS Ventura or later, if it still won't open, go to System Settings → Privacy & Security and click Open Anyway near the bottom.
4
Import your subscription URL
Click Profiles in the sidebar → + → paste your subscription URL → Import. Your node list appears when it's done.
5
Pick a node and enable the proxy
On the Proxies page, pick a low-latency node and turn on System Proxy. Apps that follow the system proxy, like Safari and Chrome, will use it.
FlClash · Installing on Android
1
Download the APK
Download the FlClash APK. The Universal build works on most phones; newer 64-bit devices can use the smaller arm64-v8a build.
2
Allow installs from unknown sources
Open the downloaded APK. When the system asks, enable Allow from this source under Install unknown apps.
If Google Play Protect shows a warning, tap Install anyway. FlClash is open source, and its code is publicly available on GitHub.
3
Install and open FlClash
Once installed, open FlClash and follow the first-run prompts to finish the basic setup.
4
Add your subscription
Go to Profiles → + in the top right → choose URL → paste your subscription URL → save and wait for the nodes to load.
5
Start and allow the VPN
Back on the home screen, pick a node, tap the Start button in the bottom right, and tap OK on the system VPN connection request.
About iOS: iPhone and iPad don't allow sideloading, so you'll need a third-party App Store client that supports Clash configs. The apps below are paid and available on App Stores outside mainland China (for example, the US store); you need an Apple ID from one of those regions to buy them.
SR
Shadowrocket
Paid · App Store (outside mainland China)
One of the most widely used proxy tools on iOS. Supports Shadowsocks, VMess, Trojan, VLESS and more, and imports Clash subscriptions directly. A good choice for a basic iPhone setup.
Best for beginnersClash subscription supportRule matching
St
Stash
Paid · App Store (outside mainland China)
Designed around the Clash config format, with native support for proxy groups, rule sets and overrides. Ideal if you already know Clash configs and want the same experience on iOS.
Native Clash configProxy groups & overrides
QX
Quantumult X
Paid · App Store (outside mainland China)
A powerful tool for advanced users, with JS scripting, rewrites and complex rules. It can use Clash subscriptions via a resource parser. Best if you need deep debugging.
JS scriptingRewrites & debugging
How do I import a subscription? Find the subscription or config section in the app, choose to add from a URL, and paste the subscription URL from your provider to sync your nodes.
Clash Verge Rev · Installing on Linux
1
Choose a package format
Clash Verge Rev ships as .deb (Debian / Ubuntu), .rpm (Fedora / openSUSE) and other formats. Pick the package for your distro.
2
Install the package
Debian / Ubuntu (.deb)
sudo apt install ./clash-verge_*.deb
Fedora / openSUSE (.rpm)
sudo dnf install ./clash-verge-*.rpm
3
Install Service Mode (required for TUN)
After the first launch, go to Settings → System Settings → Service Mode, click Install, and enter your sudo password in the auth prompt. This enables transparent TUN proxying.
Some minimal desktop environments lack a polkit agent, so the auth prompt never appears. Install polkit with your distro's package manager and try again.
4
Import your subscription URL
Click Profiles in the sidebar → + → paste your subscription URL → Import, then wait for the node list to load.
5
Pick a node and enable the proxy
On the Proxies page, run a latency test, pick a node and turn on System Proxy. For programs that ignore the system proxy, like terminal commands, enable TUN mode.
About the core: Mihomo (formerly Clash.Meta) is today's mainstream Clash core, supporting Shadowsocks, VMess, Trojan, VLESS, Hysteria2, TUIC and more. GUI clients (Clash Verge Rev / FlClash) already bundle it, so no separate install is needed. This section is for advanced users running servers, routers or headless Linux.
Mihomo · Deploying on a Linux server / headless system
1
Download the Mihomo binary
Grab the archive for your architecture from Mihomo's GitHub Releases:
mihomo-linux-amd64-*.gz: x86_64 servers
mihomo-linux-arm64-*.gz: ARM servers / Raspberry Pi
Enable the external controller in config.yaml to manage nodes and rules from a web dashboard such as metacubexd or Yacd:
external-controller: 0.0.0.0:9090
secret: your-api-secret # Always set a secret if exposed publicly
Subscriptions
How to add a subscription URL in Clash
A subscription URL is an online config address from your provider. Clash uses it to fetch and update all your nodes automatically, so you never have to add them one by one.
1
Get your subscription URL
Log in to your provider's dashboard, find the Clash subscription or subscription URL, and copy the full address starting with https://.
2
Open the Profiles page
In the client's sidebar, open Profiles (in both Clash Verge Rev and FlClash).
3
Add a new subscription
Click + or New, paste the subscription URL, and optionally give it a recognizable name.
4
Import and wait for the update
Click Import or Save. The client downloads the node config and fills in the node list automatically.
5
Select the profile and test latency
Switch to the newly imported profile, run a latency test on all nodes on the Proxies page, pick a low-latency node and turn on the system proxy.
No subscription yet? See our provider recommendations and how to pick one that works with Clash.
Keep it private: Your subscription URL contains account credentials. Don't share it, or others may use up your data.
Update regularly: Providers may change node addresses. If nodes stop working, click Update first to pull the latest config.
Auto-update: In Clash Verge Rev, you can set an update interval (e.g. 24 hours) when editing a subscription, so it stays current on its own.
Import failed? Make sure the URL is complete with no extra spaces. If the subscription server isn't reachable directly, connect through an existing node and try again.
Config file
Clash config file explained
Clash uses YAML config files. Learn a few key fields and you can customize ports, proxy groups and routing rules to fit your needs.
mixed-port
Mixed proxy port
Listens for both HTTP and SOCKS5, usually on 7890. If the port conflicts, change it in the client settings.
proxies
Node list
Defines every proxy node, including SS, VMess, Trojan, VLESS, Hysteria2, TUIC and more. Filled in automatically when you import a subscription.
proxy-groups
Proxy groups
Bundle nodes into groups for manual selection, automatic latency testing, failover, load balancing and other strategies.
rules
Routing rules
Decide whether traffic goes through the proxy, connects directly or gets blocked, based on domain, IP, GeoIP and more. This is how you keep local traffic direct and send the rest through the proxy.
dns
DNS settings
Use different resolvers for local and overseas domains to avoid DNS poisoning and leaks. Especially important in TUN mode.
Master these features to make Clash more flexible and more reliable.
TUN mode (system-wide transparent proxy)
Captures all system traffic through a virtual network adapter. Ideal for games and apps that don't support proxy settings.
Clash Verge Rev: install Service Mode first, then enable TUN Mode in settings
FlClash (Android): the default VPN mode already proxies everything
Pair it with proper DNS settings to avoid DNS leaks
All trafficGamingAdmin rights required
Proxy group strategies (Proxy Groups)
Combine nodes into groups with different strategies for smart switching.
select: pick a node manually in the panel
url-test: tests periodically and uses the lowest-latency node
fallback: switches to a backup when the primary node fails
load-balance: spreads connections across multiple nodes
Auto latency testHigh availability
Rule-based routing (local direct · rest via proxy)
Use the rule engine to control exactly where traffic goes, balancing speed and privacy.
DOMAIN-SUFFIX: match by domain suffix
IP-CIDR: match by IP range
GEOIP,CN,DIRECT: mainland China IPs connect directly
RULE-SET: reference an external rule set
Local traffic directFine-grained routing
Rule Provider (online rule sets)
Use rule-providers to reference remote rule files that update automatically from upstream, with no manual upkeep.
Supports YAML / text / mrs formats with a configurable update interval
Popular community rules: Loyalsoldier/clash-rules, ACL4SSR
Reference multiple rule sets at once, matched in order
Auto-updateCommunity rules
DNS anti-poisoning setup
The right DNS settings prevent poisoning and leaks, keeping lookups accurate.
Resolve domestic domains with a local (domestic) DNS such as 223.5.5.5 (AliDNS) or 119.29.29.29 (DNSPod)
Resolve overseas domains with encrypted DNS (DoH / DoT)
fake-ip mode speeds up DNS responses
Use nameserver-policy to resolve domains by group
Anti DNS poisoningEncrypted DNS
External controller & live monitoring
A built-in RESTful API lets you watch traffic, switch nodes and manage connections in real time from a web dashboard.
Set the listen address with external-controller, commonly port 9090
Works with web dashboards like metacubexd and Yacd
Manage the core on a router or server remotely
See which rule each connection matched, handy for debugging
Web dashboardAPI control
FAQ
Clash frequently asked questions
The most common install, config and connection issues, and how to fix them.
My browser still can't load websites after installing. What should I do?
Check the following in order:
Make sure the client's System Proxy switch is on
Run a latency test in the proxy panel to confirm your selected node works
Check whether a browser proxy extension is overriding system settings; if so, set its proxy to 127.0.0.1:7890
If the system proxy doesn't help, try enabling TUN mode
Subscription import fails or shows 0 nodes. What now?
Subscription expired: log in to your provider's dashboard for a fresh URL
Subscription server unreachable: connect via another network or node, then import again
Incomplete URL: make sure it starts with https:// and has no extra spaces
Incompatible format: check with your provider that they offer a Clash-format subscription
Clash Verge Rev asks me to install "Service Mode". Is that safe?
Service Mode is a system service component bundled with Clash Verge Rev that lets TUN mode run without asking for elevated permissions every time. Being asked for an admin password during install is a normal system authorization step.
If you don't need TUN mode, you can skip it and just use the system proxy.
How do I route games and desktop apps through the proxy?
Clash Verge Rev (Windows / macOS / Linux):
Install Service Mode under Settings → System Settings
Turn on TUN Mode; from then on, all system traffic goes through Clash
FlClash (Android): Runs as a VPN by default, so it already proxies everything.
How do I fix "port 7890 is already in use"?
Usually an old Clash process didn't exit, or another app is using the port:
Fully quit Clash and start it again
Change the mixed port to another value (e.g. 7891) in the client settings
After changing it, update the proxy port in browser extensions or other apps too
How do I make it start automatically at login?
Clash Verge Rev: Turn on Auto Launch under Settings → System Settings.
FlClash (Android): Allow FlClash to auto-start in system settings, and turn off battery optimization for it so it isn't killed in the background.
How do I troubleshoot high latency or frequent disconnects?
Run a latency test on all nodes and switch to a faster one
Update your subscription; old nodes may no longer work
Peak-hour congestion is common; try nodes in another region
On networks with heavy packet loss, UDP-based protocols like Hysteria2 / TUIC usually perform better
Check your local network, and test over a wired connection if needed
What's the difference between a subscription URL and a config file?
A subscription URL points to a remote config hosted on a server. The client pulls it periodically, so node changes sync automatically. It's the right choice for most users.
A local config file is a YAML file stored on your device. You can edit its rules and proxy groups yourself, which suits users who want deep customization.
Both use the same format; a subscription URL is essentially a YAML config you can fetch remotely.
Is there a free Clash client for iOS?
Right now, full-featured iOS clients that support Clash configs are essentially all paid apps, such as Shadowrocket, Stash and Quantumult X, each a one-time purchase. See the iOS install notes and the iOS client comparison.
Android shows a security warning when installing the APK. What should I do?
This is the system's standard warning for apps from outside an app store:
If Google Play Protect shows a warning, tap Install anyway
Or grant permission to your file manager or browser under Settings → Apps → Special app access → Install unknown apps
Only download APKs from official sources such as the project's GitHub Releases.
Ready to get started?
Head to the download center for the latest clients, or compare 14 clients by platform, maintenance status and core.