Shadowrocket Beginner FAQ: How to Add Servers and Turn On the Connection

Answers to 10 common Shadowrocket setup questions, covering server entries, subscriptions, Global Routing, greyed-out connections, and verification steps.

At a Glance

This guide is for iPhone and iPad users opening Shadowrocket for the first time. It covers ten common questions in order: preparing an existing configuration, importing it, choosing a routing mode, connecting, verifying, and troubleshooting. By the end, you can complete the basic setup and identify whether a problem comes from the configuration, DNS, local network, or remote connection.

1. Getting Started: Add an Existing Server or Import a Subscription

Question 1: What should be prepared before opening Shadowrocket for the first time?

Shadowrocket is a paid client for Apple platforms, available exclusively through the App Store. Before purchasing, verify the developer name, Shadow Launch Technology Limited, and app ID 932747118. iPhone and iPad are the primary devices; compatibility with Mac, Apple TV, and Apple Vision, along with all system requirements, is listed on the App Store page.

The client and the network service are separate. A one-time Shadowrocket purchase grants use of the client only; it does not generate a server address, port, password, or subscription URL. Before setup, prepare the connection details or subscription URL provided by a service you already use.

  1. Verify the app

    Open the Shadowrocket product page in the App Store and confirm that the developer is Shadow Launch Technology Limited and that the URL contains id932747118.

  2. Prepare the parameters

    Confirm whether the existing configuration uses Shadowsocks, VMess, VLESS, Trojan, Hysteria2, or WireGuard, and record every field provided by the service.

  3. Choose an import method

    For a single server, enter the details manually from the “+” in the upper-right corner of Home. For multiple servers maintained by a service, use Subscribe.

  4. Complete the first connection

    After saving, return to Home, select an entry, turn on the connection switch at the top, and allow the VPN configuration when prompted by the system.

Question 2: How do you add one existing server manually?

Open Home, tap “+” in the upper-right corner, and select the protocol in Type that exactly matches the existing parameters. Then enter Address, Port, Password, or the authentication fields required by the protocol. Port must be an integer from 1 to 65535, but the actual value comes from the existing service configuration and cannot be guessed from the protocol name.

Configurations using VMess, VLESS, or Trojan may also include TLS, SNI, Transport, Path, or WebSocket Host. WireGuard commonly uses Private Key, Public Key, Address, DNS, and Peer Endpoint. Entering only the server address and port is not enough; any mismatch can appear as a timeout or handshake failure.

2. Importing, Refreshing, and Troubleshooting Subscriptions

Question 3: How do you add an existing subscription URL?

In Home, tap “+” in the upper-right corner, set Type to Subscribe, paste your complete subscription URL into URL, and enter a recognizable Remark. The format example is https://example.com/sub?token=xxxx; example.com and xxxx are dummy values for demonstration.

After saving, return to Home. The subscription group will usually begin fetching content, and you can also update it from the list. When the update succeeds, the group will show the servers returned by the service. Selecting one does not connect automatically; you still need to turn on the Home connection switch.

Type: Subscribe
URL: https://example.com/sub?token=xxxx
Remark: My existing subscription
Update order: Save → Return to Home → Refresh the subscription → Select an entry

Question 4: What if a subscription update times out or shows no entries?

First check that the URL is complete, especially that the token parameter after the question mark was not lost during copying. A URL opening in a browser does not guarantee that its response is a subscription format Shadowrocket can read. If it returns a login prompt, blank text, or an error code, verify the original URL with the service.

If the current network cannot reach the subscription URL directly, first establish a connection using a configuration that already works, then try the update again. Subscribe-related update options in Settings can determine whether the current proxy is used, but this helps only when the existing connection itself works.

Does the subscription update keep timing out?

Switch once between Wi-Fi and cellular data, then verify that the URL is complete. If a working connection is available, enable it before retrying the update and check the Subscribe update path in Settings.

The update succeeded, but there are no servers?

Confirm that the response is not an empty group and check whether the service changed the subscription URL. Keep the original Remark before deleting anything so similarly named groups do not get mixed up.

Are old entries still there after refreshing?

First confirm that you refreshed the correct subscription group. Subscription updates generally synchronize with remote content; an independently added entry is not automatically managed by another subscription.

Does pasting show a format error?

Remove leading and trailing spaces and line breaks from the address, and confirm that you are using the complete HTTPS URL. Do not use the service’s homepage, order page, or explanatory text as the subscription URL.

Do you have to refresh manually every time?

Review the Subscribe-related update options in Settings. The actual result still depends on whether the subscription URL is reachable and what the remote response contains.

3. Choosing Global Routing and Fixing a Greyed-Out Connection Switch

Question 5: What is the difference between Config, Proxy, Direct, and Scene in Global Routing?

Global Routing determines how traffic is handled. Config matches traffic against the rules in the current configuration; Proxy sends traffic through the current proxy policy; Direct connects traffic directly; Scene switches policies according to configured network scenarios. For everyday use with a rule configuration, start with Config.

Config depends on rule order and the final rule. Common keywords include DOMAIN-SUFFIX, GEOIP, IP-CIDR, and FINAL. Shadowrocket matches from top to bottom and applies the policy specified by the first matching line; traffic not matched earlier is handled by FINAL.

Config

Recommended

Use the current Config rules to determine whether each connection uses Proxy, Direct, or Reject, allowing different domains and IP ranges to follow different paths.

Best for: Using an existing rule configuration day to day

Proxy

Skip rule matching and send all traffic to the currently selected proxy entry, making it easier to determine whether the problem comes from rule matching.

Best for: Temporarily testing proxy connectivity

Direct

Connect directly without using the current proxy entry. If selected by mistake, the connection switch may still be on while the expected routing change is not visible.

Best for: Comparing local direct-connection results

Scene

Apply policies according to preset scenarios such as Wi-Fi or cellular networks. Configure the scenario conditions before using this mode.

Best for: Automatic switching on a fixed network environment

DOMAIN-SUFFIX,example.com,PROXY
IP-CIDR,192.168.0.0/16,DIRECT
GEOIP,CN,DIRECT
FINAL,PROXY

The rules above are syntax examples only. The first line matches a domain suffix, the second sends a specified private address range to Direct, the third matches GEOIP data, and the final line handles connections not matched earlier. Actual policy names must exist in the current Config.

Question 6: What should you do if the Home connection switch is greyed out or will not turn on?

First confirm that a valid server entry is selected in the Home list. If there is only a subscription group name with no selectable entry, a manual configuration is missing required fields, or the selected entry was removed by a subscription update, fix the configuration before trying again.

The first time you turn on the connection, the system asks to add a VPN configuration. Complete the system confirmation, then return to Shadowrocket. If the previous connection did not close cleanly, turn off the switch, wait a few seconds, and turn it on again. If there is still no response, switch local networks and reopen the app.

  1. Confirm the selected entry

    Return to Home and make sure a specific server entry is selected, rather than only an empty subscription group.

  2. Check the fields

    Open the entry and verify that Address, Port, authentication fields, and protocol parameters such as TLS, SNI, and Transport are complete.

  3. Confirm the system request

    During the first connection, complete the VPN configuration confirmation shown by the system, then return to Home to operate the switch.

  4. Reset the connection

    Turn off the current connection, wait a few seconds, and turn it on again. Then test on both Wi-Fi and cellular data to rule out a single-network restriction.

  5. Check Log

    Open the relevant diagnostic or Log page and distinguish errors at different stages, such as DNS failure, timeout, and TLS handshake.

4. How to Confirm That a Connected Status Is Actually Working

Question 7: How can you verify that the connection is working after turning it on?

Do not rely on the switch color alone. In Home, use Connectivity Test to check basic connectivity, then open a page that was not previously cached and observe the result. If Global Routing is set to Config, also confirm which rule the test domain actually matched.

Then check Data or Log. Data shows whether upload and download traffic is being generated during the connection; Log shows domain resolution, rule matches, target addresses, and connection errors. If a page opens but Log shows Direct, inspect the rules instead of repeatedly changing protocol parameters.

4 modes
Global Routing:Config / Proxy / Direct / Scene
4 types
Core rules: DOMAIN-SUFFIX / GEOIP / IP-CIDR / FINAL
1–65535
Valid integer range for a network port; the actual value comes from the existing configuration
932747118
App Store product page app ID

Question 8: Why does a page remain inaccessible even though latency has a value?

A latency test only shows that one probe received a response; it does not prove that DNS resolution, the TLS handshake, and the target page request will all succeed. A common pattern is normal list latency followed by DNS failure in Log. TCP may also connect successfully before the session stops because TLS or transport parameters do not match.

For troubleshooting, first use Direct to compare the local network, then use Proxy to temporarily bypass Config rules. If Direct works but Proxy fails, focus on the selected server and protocol fields. If Proxy works but Config fails, check rule order, policy names, and FINAL. If both fail, inspect the local network and DNS.

Observed result Check first Next step
Latency keeps timing out Address, Port, and local network Switch between Wi-Fi and cellular data, then compare the service parameters
Normal latency but DNS failure DNS settings in Settings Restore known-working settings and test the domain resolution again
Proxy works, Config does not Rule order and policy names Check which rule actually matched in Log
Disconnects immediately after the handshake TLS, SNI, Transport, and authentication fields Compare each item with the original configuration; do not mix protocol parameters

5. Using On Demand and Finding Errors in a Broken Configuration

Question 9: What is On Demand, and why does it connect automatically when enabled?

On Demand triggers connections based on network conditions. Open it from Settings → On Demand. Before enabling it, make sure manual connections are stable, then add Wi-Fi or cellular conditions. Otherwise, automatic triggers will only repeat the original configuration error.

After setup, test three states separately: connect to the specified Wi-Fi, leave that Wi-Fi and switch to cellular data, and lock then wake the device. Check whether the Home switch and system connection status change as expected. If the behavior is reversed, check whether the condition means “connect when matched” or “disconnect when matched.”

  1. Verify manually first

    In Home, select a server and use Config or the required Global Routing mode. Confirm that web access and Log both work normally.

  2. Open Settings

    Open Settings → On Demand and check for existing conditions to avoid conflicting results from multiple conditions.

  3. Add a condition

    Set Wi-Fi or cellular conditions as needed, and specify whether a match should connect or disconnect.

  4. Switch networks

    Switch between the specified Wi-Fi and cellular data, then wait for the system network transition to finish before checking the connection status.

  5. Check wake behavior

    Lock and wake the device again to make sure On Demand is not repeatedly connecting or disconnecting because of an old condition.

Question 10: How can you quickly locate the failing layer when there are many settings?

Troubleshoot with the “minimum working configuration.” Keep one server with clear parameters, temporarily set Global Routing to Proxy, and turn off On Demand so Scene and complex rules do not affect the result at the same time. After the basic connection works, restore Config, DNS changes, and automatic triggers one at a time.

Read Log in chronological order. A resolution error occurs before the target connection is established; a timeout usually requires checking reachability, address, and port together; a TLS handshake error calls for checking TLS, SNI, and authentication; a rule match error means returning to Config to inspect the order of DOMAIN-SUFFIX, GEOIP, IP-CIDR, and FINAL.

Should you change the protocol first or check Log first?

Check Log first. The protocol is determined by the existing service configuration and should not be changed arbitrarily for troubleshooting. Use symptoms such as timeout, DNS failure, or TLS handshake to identify the relevant fields.

Does everything use Direct after Config loads?

Confirm that Global Routing is actually set to Config, then check whether an overly broad Direct rule appears near the top and which policy FINAL points to.

Wi-Fi works, but cellular data times out?

Keep the same server and Global Routing mode for comparison, and check whether On Demand assigns a different action to cellular data.

Did the original configuration stop working after a subscription update?

Select a valid entry from the updated subscription, verify that the policy group names referenced still exist, and check that the protocol fields returned by the service are complete.

After completing these ten checks, a practical daily setup is: select a valid entry in Home, use a verified Config for Global Routing, update subscriptions as needed, and enable On Demand only after manual connections are stable. When a problem occurs, record the current network, selected entry, routing mode, and Log keywords before changing one setting.

Download on the App Store