If you tapped Don’t Allow
Go to Settings → General → VPN & Device Management (older systems may say VPN only). Delete the Shadowrocket row, return to the app, and flip the switch so the system asks again.
Written from the official app already on the Home Screen. Follow the steps. No nodes or subscriptions.
Shadowrocket is a client, not a carrier. Missing any one of them, no amount of UI fluency will get you through. Download, switching regions, and spotting fakes: download page. Meanings: glossary. This handbook assumes the icon is already on the Home Screen.
| Required | Where it comes from | If you don’t have it |
|---|---|---|
| Official app | App Store, app ID 932747118 |
Enterprise signing, IPAs, and Android wrappers are out of this handbook’s scope |
| A working line | Your own provider: a subscription URL, a QR code, or a parameter sheet | The switch flips; the tunnel is empty |
| System VPN permission | The configuration request iOS shows on first connect | The app can’t take over traffic and will keep failing |
| A working network | Wi-Fi or cellular itself is up | Switch to Direct to check; if the phone can’t get online, don’t blame the client first |
The home list is usually empty after you open it. Don’t hunt for nodes yet—finish system authorization. Permission and “do you have a line” are two different things.
“Shadowrocket” Would Like to Add VPN Configurations. This will allow the app to filter your network traffic and monitor your internet use. [Don’t Allow] [Allow]—on an official store install, this is the same door iOS gives every VPN-class app. Tap Allow. It is not malware.
Go to Settings → General → VPN & Device Management (older systems may say VPN only). Delete the Shadowrocket row, return to the app, and flip the switch so the system asks again.
After an iOS update the configuration sometimes dies. Same fix: delete the old configuration → re-authorize. Don’t reinstall first, and don’t start by changing node ciphers.
The + at the top right of Home is the load door. What you got from the provider usually belongs to only one of the rows below. Don’t try all three and end up with a pile of duplicate, expired entries.
| What you have | Door | How you update later |
|---|---|---|
| A long https subscription URL | + → type Subscribe |
Update this one row; don’t hand-build dozens of nodes again |
| A QR code | Scan, or recognize from the photo library | Scan again when the code changes; a single node will not refresh itself |
ss:// vmess:// trojan:// text |
Copy first, then see if “Add from Clipboard” appears | Same as a single node; re-import after it changes |
| A sheet of address, port, password, protocol | Fill in by protocol type | Edit the field that changed |
+, set type to Subscribe.https:// or the scheme your provider wrote; no leading/trailing spaces, no line breaks.+, choose Scan and point at a computer or another phone.Copy the shared text in full and return to Shadowrocket. If you see “configuration detected on the clipboard,” confirm add. No prompt: switch to manual, or ask the provider for a subscription URL.
In +, pick the protocol that matches the provider. The name can be yours; what actually decides whether it connects are the fields after:
| Field | What to fill | Common mistakes |
|---|---|---|
| Address / Host | Domain or IP, exactly as written | Putting the port in the address, or dropping a subdomain |
| Port | A number on its own | Left empty, or written as 443443 |
| Password / UUID | Paste as-is | An extra line break or space after an email forward |
| Cipher / transport / TLS | Match the method, path, and hostname the provider wrote | Picking whatever “looks more secure” from memory |
| Remark | Only affects how the list displays | Editing a remark will not resurrect a dead node |
A successful import does not mean the currently selected row works. Flip the switch with nothing selected and you may connect an old node—or nothing.
A successful handshake plus latency you can live with. Third-party “speed test” apps measure the whole device’s exit, which may not be the row you selected, so they can’t convict a single node.
Once when you change networks is enough. Hammering test like a refresh button will not resurrect an expired plan.
Order: select a node → pick a mode → flip the switch. “Switch on but pages won’t open” is usually the wrong mode or node, not a broken app.
Split by rules: tunnel what should tunnel, Direct the rest. Daily default. Saves power and is less likely to break local apps and the LAN.
Send as much traffic as possible into the tunnel. Good for troubleshooting, or a short spell when rules clearly missed a domain. Don’t make it the all-day default.
Same as power-off. Use it to compare “is this the client, or can the phone itself not get online.” You can stay here when you’re done.
Touch settings only after you can get online stably. If the subscription already brings rules, watch for a few days. Two maps stacked is a common reason things get “slower the more you tweak.”
A site that shouldn’t be Direct but is: switch to Proxy to verify. If it opens, go back to Config, add a rule, and write down what you changed so you can roll back. Don’t live in global for one site.
Prefer the value your provider wrote in their notes. Empty or following the system is usually safer than a random public DNS. A bad fill makes split decisions wrong: switch on, this site still won’t come out.
| Option | What it does | Advice |
|---|---|---|
| MITM / HTTPS decryption | Install a certificate and split open encrypted traffic | Leave it off if you don’t understand certificate chains |
| IPv6 | One more address family | Keep the default when the node and the local network aren’t ready |
| UDP | Some calls and games use it | Turn it on per the provider’s notes; don’t treat it as an accelerator |
| DoH / DoT | Encrypt DNS queries | Turn it on with documentation; don’t run several at once |
Decide the layer first: permission, subscription and nodes, or mode and rules. Don’t flip five switches at once.
| Symptom | Layer | What to do |
|---|---|---|
| Fails the moment you flip the switch | Permission | Delete the old VPN in Settings, return to the app, and allow again |
| The list is empty | Subscription | Check whether the URL is complete, expired, or over the device limit |
| Nodes are there but all time out | Node / local network | Switch to Direct to confirm the phone can get online, then try another row. If they all fail, ask the provider |
| Switch on, pages spin | Mode / rules / DNS | Try Proxy once; if it opens, a rule was missed—go back to Config and add it |
| Only some apps fail | Split routing | Verify with Proxy the same way. Edit rules after you’re sure. Don’t reinstall first |
| Especially power-hungry or hot | Habit / node | Switch back to Config, use Direct when idle, and avoid nodes that clearly drop packets |
| Broken after an iOS update | System configuration | Delete the configuration and re-authorize; if that fails, reinstall the official app, then update the subscription |
| UI or signature doesn’t look official | Source | Delete it and reinstall only from the App Store. Don’t fix a crack |
Deleting the app may wipe the local list. The subscription URL is still in your email or the provider’s dashboard—walk section 03 again after reinstalling.