Clash Setup Tutorial: From Importing a Subscription to Verified Connection
Four steps, about ten minutes: import the subscription link, switch to Rule mode, enable the system proxy, and verify the connection actually works. Every step spells out where to click, what you should see, and what comes next, so you can follow along and finish your first setup.
- Works across all platform clients
- No prior experience needed
- About 10 minutes to complete
Before You Begin: Two Things You'll Need
This tutorial assumes you already have a client installed and hold a subscription link. If either is missing, sort that out first.
First: a Clash client already installed.The download page on this site lists currently maintained clients by platform — Windows, macOS, Android, iOS, and Linux — with Clash Plus as the top pick across all platforms; installation is no different from any other software. If you haven't installed one yet, do that first and launch it once to confirm it opens normally.
Second: a subscription link.A subscription link is a URL starting with https:// provided by your service provider, which the client uses to download a configuration file containing nodes and routing rules. It's usually found in your provider's account center under "Subscription," "One-Click Import," or "Copy Subscription URL." Treat the subscription link like a login credential — never paste it somewhere public. For how subscriptions, config files, and nodes relate to each other, see the corresponding entry in the Glossary; we won't go into detail here.
Menu naming varies slightly between clients: the subscription management page is called "Subscription" or "Profiles" in Clash Plus and Clash Verge Rev, and "Profiles" in FlClash; the proxy mode switch sits on the home screen in some clients and at the top of the Proxies page in others. This guide describes things as "feature name (common alias)" — just find the entry with the same meaning in your own client, since the underlying logic is identical across all of them.
Step 1: Import the Subscription Link
Goal: get the client to fetch the config file so a usable profile card shows up in the subscription list.
Start by finding the subscription address in your provider's account center and clicking "Copy Subscription Link" to copy the full URL to your clipboard. Make sure you're copying the link itself, not a QR code on the page or a client-specific one-click import button — the plain link works in every client and is also the easiest to troubleshoot.
Back in the client, go to the subscription management page: in Clash Plus and Clash Verge Rev this is labeled "Subscription" (or "Profiles" in the English UI) in the left sidebar, while in FlClash it's called "Profiles" at the bottom or in the side panel. At the top of the page there's an input field or a "New / Import" button — choose Import from URL, paste the link you just copied, and click "Download" or "Import." The client will send a request to that address, and within a few seconds a new profile card should appear in the list, usually showing the subscription name, last update time, and traffic info.
Once the card shows up, there's one last action left: click the card to set it as the active profile. Most clients indicate the active profile with a highlighted border or a checkmark. Skipping this step is the most common mistake beginners make — the subscription imports fine, but the connection never works afterward, usually because the client is still using its default blank profile.
If the import fails with a download error, check these in order: whether the link was copied in full (a truncated ending is common), whether your current network can reach the provider's subscription domain, and whether the subscription has expired. A few providers only offer subscription addresses in other formats, which need to be converted before the Clash client can read them — see the "Subscription Conversion" entry in the Glossary for how that works; for the more advanced case of merging multiple subscriptions, see the local overrides and multi-subscription chapter in the Advanced Guide.
Once you've confirmed the card is selected, move on to choosing a proxy mode.
Step 2: Choose a Proxy Mode and Pick a Node
Goal: switch to Rule mode and select a node with normal latency in the policy group.
Once the profile is active, a mode switch will appear on the client's home screen or at the top of the Proxies page, typically with three side-by-side options: Rule, Global, and Direct. The difference in one line: Rule mode evaluates each connection against the routing rules in the config file, sending traffic through the proxy or straight through as appropriate, with domestic traffic in mainland China going direct; Global mode skips that evaluation and routes everything through the proxy; Direct mode is effectively the same as turning the proxy off temporarily. In the config file, this corresponds to the value of the mode: rule field.
For everyday use, stick with Rule mode. It balances speed and data usage well: local sites load directly without wasting subscription traffic, while sites outside China are automatically matched against proxy rules without any manual switching. Global mode should only be used temporarily when troubleshooting "is this site actually being missed by the rules" type issues, then switched back afterward — leaving it on Global long-term routes all local traffic through the proxy too, costing you both speed and data.
With the mode set, go to the Proxies page to pick a node. You'll see several policy groups — pre-arranged node groupings set up by the subscription provider, commonly including manual-select groups named something like "Proxy Select" or "PROXY," as well as automatic groups like "Auto Select" or "Fallback." Expand a manual-select group, click Test Latency once (usually a lightning bolt or radar icon next to the group name), wait for a millisecond value to appear next to each node, then pick one with a low number — the smaller the number, the faster the response, and any node showing "timeout" is currently unavailable and should be skipped. If the group includes an "Auto Select" option, choosing it lets the client periodically test speeds and switch to the fastest node automatically, which suits users who don't want to manage this manually.
Policy groups also include other types like load balancing; the behavioral differences and real-world setup strategies for each type are advanced topics covered in the Policy Groups chapter of the Advanced Guide; if you want to try editing routing rules yourself, start with the Rule Set Management chapter for the basics. For the main path of this tutorial, all you need at this point is: mode set to Rule, a node selected — now on to step three.
Step 3: Enable the Connection
Goal: get system traffic actually routing through the client. Turn on system proxy on desktop; start the VPN tunnel on mobile.
The first two steps only got the profile ready — traffic still isn't passing through Clash yet. You need to explicitly turn on the takeover switch, and the exact steps differ slightly by platform.
Windows and macOS:Find the System Proxy switch on the client's home screen or in Settings, and turn it on. This switch points the operating system's proxy settings to the client's local listening port, and browsers and most apps that respect system proxy settings will immediately start routing through Clash. On macOS, an authorization dialog may pop up the first time — enter your system password to confirm. Note that system proxy doesn't cover every program — some command-line tools and games ignore system proxy settings, and that traffic requires TUN mode instead; see the TUN chapter in the Advanced Guide for how it works and how to enable it, though you don't need to worry about it for your first setup.
Android:Tap the prominent start button on the client's home screen, and the system will show a confirmation dialog asking "XX wants to set up a VPN connection" — tap "OK." This is Android's standard authorization flow for all proxy-type apps; once authorized, a key icon appears in the status bar, indicating the VPN tunnel is established and all app traffic will now pass through the client.
iOS:On first launch, the system will ask to "Add VPN Configurations" — tap Allow and authenticate with Face ID or your passcode. After that, just tap the connect switch inside the app, and the VPN status in Settings will sync to show Connected.
Regardless of platform, once the switch is successfully turned on, the client's home screen will usually show live upload/download speed numbers. Seeing those numbers move means traffic is flowing through the client, and you can move on to the final verification step; if the switch snaps back off immediately after turning it on, it's usually because the port is already in use by another proxy app — quit any other similar software first and try again.
Step 4: Verify the Proxy Is Working
Goal: confirm the connection is genuinely working using two pieces of evidence — pages load, and the connections panel shows matching records.
The first piece of evidence comes from your browser.Open a website that was previously inaccessible — if it loads normally, the proxy chain is basically working. It's best to test in a private/incognito window to avoid browser cache creating a false impression that "it's working" when it isn't.
The second piece of evidence comes from the client itself.Go back to the client and open the Connections panel — on desktop clients this is usually in the sidebar, and in some clients it sits next to the Logs page. Refresh the page you just tested, and the panel should keep adding new connection entries, each showing the target domain, the rule it matched, and the node actually used. Check two things: connections to sites outside China should be going through your selected proxy node, while connections to local domestic sites should be matching the direct-connection rule. If both hold true, rule-based routing is working as expected, and your first setup is complete.
If a page still won't load, check three things in order.First, go back to the Proxies page and run a latency test on the current node again — if it shows a timeout, switch to another node and retry, since a single bad node is the most common cause; second, confirm the switch from step 3 is still turned on, since system proxy settings can get reset after some systems wake from sleep; third, check whether your subscription has run out of data or expired, which is usually shown directly on the subscription card. If all three check out and it's still not working, consider rule- or DNS-level issues next: some sites fail to load due to DNS poisoning, and the diagnosis method along with fake-ip and DNS optimization options are covered in the DNS chapter of the Advanced Guide.
One more thing worth noting: passing verification doesn't mean you're set forever. Subscription providers rotate nodes periodically, so it's worth enabling automatic scheduled updates for your profile on the subscription page (most clients support setting an interval by hour or day) — a node list that's never refreshed is another common reason connections stop working over time.
After This: Where to Go Next
With the four steps done, you're already set up for everyday use. If you want to go further, pick from the following as needed.
-
Understand the concepts so terminology stops being a guessing game
Terms like policy groups, Fake-IP, GEOIP, and mixed-port keep showing up in config files. The Glossary organizes clear explanations by category — proxy protocols, rule routing, networking, and DNS — making it a handy reference to check whenever you need it.
-
Edit your own config to route traffic your way
The Advanced Guide systematically covers policy group design, rule-set-as-subscription management, DNS optimization, TUN mode, and merging multiple subscriptions. It's the site's in-depth reference document — a good place to start is the Rule Sets chapter.
-
Switch clients, or set one up on another device
Different platforms and habits call for different clients. The download page organizes all currently maintained options by platform along with system requirements, version info, and usage notes.
This page only covers the main path from zero to working. Anything involving config file field changes or core behavior differences is consolidated in the Advanced Guide and Glossary, and won't be repeated here.