Setting up Shadowrocket on an iPhone is straightforward once the subscription link, client permissions, and routing mode are understood. The important part is not only adding a URL. You also need to confirm that the subscription was imported successfully, refresh the available servers, select an appropriate profile, allow iOS to create the VPN configuration, and verify that the application traffic is using the intended connection.

This guide explains the complete workflow from preparation to verification. It focuses on normal configuration and diagnosis rather than promising that every server will work for every website or application. A subscription provides configuration information; it does not guarantee identical performance across all networks, regions, destinations, or times of day.

What You Need Before Importing

Shadowrocket is an iPhone network utility that can use subscription-based configurations and individual server profiles. The application itself does not provide a subscription. You need a valid link from your VPN provider or from an administrator who manages the configuration. Depending on the service, the link may contain encoded information, a token, or a long address with query parameters. Copy the entire URL rather than only the visible beginning.

Before opening Shadowrocket, check the following items:

  • ✅ Shadowrocket is installed from the official App Store listing supported by your Apple account region.
  • ✅ The subscription URL is copied without spaces, line breaks, or missing characters.
  • ✅ Your account has an active plan or an otherwise valid configuration source.
  • ✅ Your iPhone can temporarily access the provider’s account page or subscription delivery page.
  • ✅ No other VPN, DNS, proxy, or device-management profile is actively controlling the connection.
  • ❌ Do not paste a private subscription URL into a public chat, screenshot, issue tracker, or online converter.

The subscription URL and the server address are not always the same thing. A subscription URL normally retrieves a list of profiles and may later be used to update them. A single server configuration is often static and may not receive future changes. If your provider offers both options, use the subscription method unless you specifically need to add one manually.

1

Subscription URL

1

iPhone client

3

Main checks

The three main checks are configuration availability, tunnel permission, and traffic verification. A profile appearing in the list only proves that the configuration was imported. It does not prove that the selected server is reachable or that the application you are testing is using the proxy.

How to Add the Subscription URL

Open Shadowrocket and look for the section that manages subscriptions, often presented as a subscription or configuration management area. The exact button name can change between application versions, so focus on the function rather than a particular label. Choose the option for adding a subscription, then paste the complete URL into the address field.

Some providers make the process easier by offering an “open in Shadowrocket” link or a copy button. If you use an open-in-app link, iOS may switch directly to Shadowrocket with the URL filled in. Review the address before saving. A deep link can open the client, but it does not remove the need to confirm that the correct subscription was added.

  1. Copy the full subscription URL from your provider’s account page.
  2. Open Shadowrocket and enter the subscription management screen.
  3. Tap the add button or the equivalent option for a remote subscription.
  4. Paste the URL into the URL field.
  5. Give the subscription a recognizable local name if the client offers a name field.
  6. Save the entry and wait for the client to retrieve the configuration list.

After saving, inspect the result instead of immediately tapping the connection switch. A successful import should normally produce a subscription entry, a refreshed profile list, or both. If the entry is present but contains no usable profiles, the URL may be expired, the provider may have returned an error, or the client may not support the format delivered by that link.

Checking the Import Result

Look for the subscription name, its last update information, and the number or names of the available profiles. Do not assume that a familiar country or city name means the connection is already active. At this point, you are only checking whether Shadowrocket received and stored the configuration.

If the import fails, first compare the copied URL with the original. A missing character at the end of a token can make the whole request invalid. Next, try opening the provider’s account page in Safari to confirm that the iPhone has a working internet connection. If Safari works but the subscription update fails, the issue may be an expired link, an account status problem, a temporary server response, or a format mismatch.

Refresh the List and Select a Profile

Subscriptions can change over time. Providers may add, remove, rename, or replace profiles without requiring you to create a new entry. Use the update or refresh action inside Shadowrocket when the list looks outdated or when a previously working profile disappears. Keep the original subscription entry and refresh it rather than repeatedly adding the same URL.

After the update completes, review the available names and choose a profile based on your actual purpose. A nearby regional profile may be a sensible first test for ordinary browsing, while a different region may be required for a specific service that officially supports access from that region. The name alone cannot reveal current congestion, route quality, or whether a destination accepts the address.

What you see What it usually means What to do next
Subscription entry with profiles The configuration was retrieved Select one profile and test the connection
Entry exists but the list is empty The response may be invalid, unavailable, or unsupported Check the URL, account status, and provider format
Old profiles remain after an update The refresh may not have completed or the provider kept the same list Check the update result and retry once on a stable network
A profile connects but a service fails The route or application policy may not suit that destination Test another profile and inspect the routing mode

Shadowrocket configurations may use different protocols, including Shadowsocks, VMess, Trojan, Hysteria2, or WireGuard-style profiles when the supplied configuration and client version support them. These are not interchangeable labels for speed. Protocol compatibility depends on the profile format, server-side settings, transport parameters, and the client’s implementation. Avoid editing advanced fields unless the provider gives exact values.

For a first test, select one profile and leave advanced options unchanged. If it fails, changing several parameters at once makes the cause harder to identify. Record which profile you tested, whether the tunnel switch changed state, and which application produced the error.

Connect and Allow the iOS VPN Permission

Once a profile is selected, return to Shadowrocket’s main screen and turn on the connection switch. The first connection normally causes iOS to display a permission request asking to add or use a VPN configuration. Confirm the request only if you intended to connect through Shadowrocket. iOS may require the device passcode, Face ID, or another system confirmation before the configuration becomes active.

This permission is controlled by iOS, not by the subscription provider. If you deny it, Shadowrocket may show a selected profile without being able to create the system tunnel. You can review installed VPN configurations in the iPhone settings if the permission prompt does not appear again. The exact menu wording can vary by iOS version, but look for VPN or device-management settings rather than reinstalling the application immediately.

  • ✅ Select the intended profile before switching the connection on.
  • ✅ Approve the iOS VPN configuration request when you recognize it as coming from Shadowrocket.
  • ✅ Wait for the VPN indicator or the client’s connected state before opening the test application.
  • ✅ Keep one primary VPN client active while testing.
  • ❌ Do not switch between two VPN applications during the same diagnosis.
  • ❌ Do not interpret an iOS permission approval as proof that the remote profile is reachable.

Shadowrocket may offer global, rule-based, or direct routing modes depending on the installed version and configuration. Global mode generally sends covered traffic through the selected proxy, while rule-based mode decides according to domain, IP, or policy rules. Direct mode bypasses the proxy for traffic selected by the configuration. The names and available choices can differ, so read the current mode shown in the application.

Rule-based routing is often more practical when local services should remain direct and only selected destinations should use the proxy. However, a rule set can also create confusing results if it is outdated or incomplete. If a website works in global mode but not in rule mode, compare the rules before blaming the profile. Conversely, if only one application fails, check whether that application is covered by the selected policy.

Connection rule: A green or connected indicator confirms that the local tunnel was established; it does not confirm that every application or destination is routed through the same profile.

Verify That Traffic Uses the Selected Connection

Verification should happen in stages. First, check the status shown by Shadowrocket. Second, open an IP-check page in the same browser or application you intend to use. You can use the site’s IP Check page to inspect the visible public exit location. Compare the result with the selected profile name, but remember that profile labels and public IP databases may not always match perfectly.

Third, test the actual application that matters to you. A browser request and an app request can follow different paths when rule-based routing, app-specific handling, or system proxy behavior is involved. If the browser shows the expected exit but another application behaves as if it is direct, the application may be excluded by the rules or may use a connection method that is not covered by the selected configuration.

Check more than the country label. Consider whether the public IP changes when you switch profiles, whether DNS-related behavior is consistent with the route, and whether the same profile remains selected after the application is restarted. A single successful page load is useful but limited. A proper check also includes login, navigation, and the specific service function you need, provided that the service’s own regional and account rules allow it.

Verification layer Question Interpretation
Client status Does Shadowrocket show an active tunnel? Confirms local connection state, not destination access
Public IP Does the exit appear as expected? Confirms the visible route for that test request
Application test Does the required app use the route? Checks rule coverage and app-specific behavior
Session stability Does the route remain selected during use? Helps identify profile changes or intermittent access

If you need a more detailed diagnosis, temporarily simplify the test. Use one profile, one application, and one routing mode. Close and reopen the affected application after connecting, because some applications establish their network session before the tunnel is active. Also avoid changing the iPhone’s Wi-Fi or cellular network during the test unless network switching itself is what you are investigating.

Common Problems and Practical Fixes

The subscription will not import

Confirm that the URL is complete and has not been wrapped onto multiple lines. Check whether the subscription requires an active account or whether the provider has issued a replacement link. If the address works in Safari but not in Shadowrocket, the returned format may not be compatible with the client, or the provider may require a specific user-agent or conversion format. In that situation, ask the provider for the Shadowrocket-compatible subscription method instead of modifying random parameters.

Profiles are visible but do not connect

Try another profile from the same subscription and confirm that the iPhone has normal internet access without Shadowrocket. If every profile fails, the issue may be the account, subscription response, client permission, or current network. If only one profile fails, its server or transport parameters may be unavailable. Do not repeatedly toggle the tunnel while changing many settings; make one controlled change at a time.

The tunnel is connected but the application fails

Review the routing mode first. The application may be using direct traffic because its domain or IP range is excluded by the rules. Try the same destination in a different mode only as a diagnostic comparison, then return to the mode that best matches your normal use. Clear stale application sessions by closing and reopening the app, but do not repeatedly sign in and out if the service may treat frequent location changes as unusual.

The connection stops after changing networks

Moving between Wi-Fi and cellular data can interrupt an existing tunnel. Turn the connection off, wait for the network to stabilize, and turn it on again. If iOS has retained a stale VPN state, review the installed VPN configuration and confirm that Shadowrocket remains the selected client. Rebooting should be a later step, not the first response to every failed request.

  • ✅ Test the subscription link independently from the selected profile.
  • ✅ Test the profile independently from the application’s own login or content problem.
  • ✅ Compare global and rule-based behavior only for diagnosis, then choose a deliberate default.
  • ✅ Refresh the subscription when profiles are clearly outdated.
  • ❌ Do not publish or forward a private subscription URL while requesting support.
  • ❌ Do not assume that changing protocols or advanced fields will fix an account or regional policy issue.

Safe Maintenance and Final Checklist

Once Shadowrocket is working, maintenance should be simple. Keep the subscription entry instead of creating duplicates. Refresh it when the provider announces route changes or when the profile list is outdated. If a refresh produces a different set of names, select the new profile deliberately and repeat the IP and application checks rather than assuming that the previously selected item was replaced correctly.

Review permissions and routing after major iOS updates, application updates, or changes to your provider account. A client update may change labels or supported formats, while an iOS update may display a permission request again. These changes do not automatically mean that the subscription is invalid.

For privacy, keep the subscription URL out of backups or shared notes that other people can access. If you believe the link has been exposed, request a replacement or reset from the provider when that option is available. When contacting support, provide the client version, iOS version, general failure symptom, and the time of the test, but redact the private URL and account credentials.

Final takeaway: A reliable Shadowrocket setup has four separate stages: import the subscription, refresh and select a profile, approve the iOS tunnel, and verify traffic in the application that matters. Treating these stages separately makes failures easier to locate and prevents unnecessary changes to advanced settings.

In short, start with a complete subscription URL and one unchanged profile. Confirm the client status, use an IP-check page to inspect the visible exit, and then test the actual application under the selected routing mode. If something fails, isolate the layer that failed before replacing the entire configuration. For a broader introduction to subscription clients and first-time configuration, continue with the Quick Start Guide.