This guide is for iPhone and iPad users who have downloaded Shadowrocket from the App Store and are getting started. First, check the app and the connection details you already have. Then distinguish system VPN configuration permission from the Home screen connection status, routing mode, and server selection. By the end, you’ll have a step-by-step checklist for your first connection instead of treating one status message as the cause of every problem.
Before you open Shadowrocket: check the app and your connection details
Shadowrocket is a paid client for Apple platforms, available through the App Store. On the product page, check the name Shadowrocket, the developer Shadow Launch Technology Limited, and app ID 932747118. Check the App Store listing for device compatibility and system requirements. The one-time app purchase and connection services are separate: buying the app does not provide a server, subscription, or service plan.
Before you begin, have connection details or a subscription URL from a service provider you already use, and make sure they’re still valid. You can open the Home screen with the app alone, but you can’t establish a proxy connection without usable connection details. Follow the information provided with your service for the protocol, address, and credentials. Don’t use example addresses from a webpage as real configuration details.
Check the product page
Find Shadowrocket in the App Store, verify the developer and app ID, then complete your purchase and install the app. If you haven’t done so yet, see our official listing verification guide.
Prepare your details
Make sure you have a server configuration or subscription URL from a service provider you already use. A subscription URL retrieves configuration; it is not proof of your App Store purchase.
Open Home
When you first open the app, identify the connection status, Global Routing, and SERVER on the Home screen. Not Connected at this point doesn’t mean installation failed; it means no connection is active yet.
Configure, then connect
Import and check your own details, select a server and routing mode, then try the connection switch. If the system asks to add a VPN configuration, read the prompt before deciding whether to allow it.
For an initial check, consider these separately: whether you obtained the correct app, imported your connection details, selected a server, and allowed the system to create a VPN configuration. Each calls for a different action; repeatedly tapping the connection switch won’t check them for you. If you have questions about a subscription’s contents or validity, contact the provider who supplied it. The app can’t fill in missing account information.
Allow VPN Configuration: What Are You Authorizing?
When Shadowrocket first tries to connect, the system may ask to allow adding a VPN configuration. This is system-level authorization on your Apple device: the app needs to create a VPN configuration to handle network requests, and the system must allow it to work with your selected connection and rules. “VPN configuration” means permission to configure networking on the device. It doesn’t mean a server has been selected or that a subscription is active.
After reading the system prompt, allow the request if you want to use the connection feature, then complete any authentication required by your device. Return to Home and check whether the switch shows a connected state. Authorization, establishing a connection, and successfully accessing a destination are three separate steps. Allowing the configuration only gives the app permission to create the network tunnel; an incorrect address, credentials, or routing setup can still prevent the connection from working.
System authorization
- When it appears
- When you first try to connect
- What it requests
- A VPN configuration on your device
- What to do
- Read the system prompt and decide whether to allow it
- What it doesn’t do
- Provide a server address or subscription
Allowing the configuration is one requirement for connecting, not confirmation that the connection succeeded.
Connecting in the app
- Where to look
- Home → Not Connected status area
- Connection target
- The server selected under SERVER
- Routing behavior
- The current mode under Global Routing
- What to check
- Connection status and actual network access
Check the connection status alongside the selected server and routing mode.
If you chose not to allow the request, don’t assume the server is unavailable. Without the required system permission, the app can’t establish the connection as expected. Before trying again, check the VPN configuration permission on your device, then return to the app and review the selected server and switch. System settings may vary by OS version; follow the labels shown on your device.
Home screen overview: status, routing, and servers
Home is the place to start when checking a connection, but each section answers a different question. Not Connected shows the current connection status. Global Routing controls how requests are routed. SERVER lets you view and choose a connection target. Connectivity Test helps check connectivity. One section alone can’t confirm that the others are configured correctly.
If you see Not Connected, first confirm that you’ve imported a configuration and selected a valid server under SERVER, then try connecting. If the switch shows connected, that only confirms the connection status; access to a particular website can also depend on server availability, DNS resolution, and how Global Routing handles the request. When testing a specific request, note the domain, routing mode, and connection status rather than capturing only the switch label.
Connectivity Test is for checking connectivity, not for purchasing, importing, or updating a subscription. Consider its results alongside what happens when you actually access a destination. If the test fails, check the selected server and network one at a time. If it passes but the destination remains inaccessible, check whether the rules route that request as expected. SERVER is where you choose the target; if the list is empty, import your own connection details first. Connectivity Test won’t create a server for you.
Global Routing: Choosing a mode for your first connection
Global Routing controls how requests are handled once a connection is established; it isn’t a “connection speed” switch. Proxy sends requests through the selected proxy. Direct connects without a proxy. Config routes requests according to the rules in the current configuration. Scene uses your scene settings. Before choosing a mode, decide what you’re trying to do: check the server itself, connect directly for comparison, or route traffic using an existing configuration.
Config
RecommendedWhen you have a rule configuration that you’ve checked, requests are matched against its rules and routed through a proxy or directly. Requests that don’t match are handled by the configuration’s fallback rule.
Best for: everyday rule-based routing with a prepared configuration
Proxy
Sends requests through the currently selected proxy, which can help rule out routing rules as a factor during a short test. Switching to this mode won’t restore an unavailable server.
Best for: briefly checking whether the selected server can handle requests
Direct
Connects directly, so you can compare direct access on the same network. This mode does not test whether a server can provide a proxy connection.
Best for: comparing direct access over your local network
Scene
Handles requests according to your configured scene conditions. Whether it works as expected depends on those conditions and related settings, not just on selecting this mode.
Best for: using scene conditions you’ve already configured and understand
If a destination is inaccessible in Config but works after temporarily switching to Proxy, check which rules match the request. DOMAIN-SUFFIX matches domain suffixes; GEOIP matches an IP address by region; IP-CIDR matches an address range; FINAL handles requests that didn’t match earlier rules. Rules are generally checked in configuration order. Review the actual configuration rather than assuming a domain will always connect directly or through a proxy based on the mode name alone.
After importing your details: complete your first check in order
If you have a subscription URL, tap “+” in the upper-right corner of Home to start adding it. Choose Subscribe under Type, paste your URL, and save. Then check whether you need to refresh to retrieve the latest content. This subscription URL is an example: https://example.com/sub?token=xxxx. It’s fictitious and won’t connect to a server. If your provider supplied individual server details, choose the matching type and fill in each field. Shadowsocks, VMess, VLESS, Trojan, Hysteria2, and WireGuard are different protocol types; changing only the name while keeping fields from another protocol won’t work.
- Check SERVER first: Make sure your configuration appears in the list and that the target you want to test is selected. If the list is empty, return to the import step. If the configuration is listed but no longer works, ask the provider who supplied it to verify the address and credentials.
- Next, check Global Routing: For an initial check, note the current mode, then compare network behavior with Proxy and Direct. If you need rule-based routing, confirm which rules are actually loaded in Config.
- Then check the connection status: Try connecting and respond to the system’s VPN configuration prompt. If Not Connected remains, check which part isn’t ready: authorization, connection details, server, or current network.
- Finally, check the test results: Consider Connectivity Test results alongside access to the actual destination. A single test doesn’t show how every request will be routed.
Importing a subscription and refreshing it are separate steps. The first import adds an existing URL to the app. A refresh retrieves the latest content supplied by the provider from that URL. If server names, counts, or settings change after a refresh, make sure the selected SERVER is still the target you intend to use before testing the connection. Refreshing doesn’t replace the provider’s responsibility for maintaining the subscription’s validity and contents.
If only some destinations are inaccessible, note the connection status and the Global Routing mode used during testing, then check whether the relevant domains match the expected rules in Config. If all destinations are affected, start by checking the device’s network, system authorization, and selected server. Recording symptoms this way helps distinguish rule issues from server problems and first-time authorization issues.
When you reopen the app: settings to check again
After the initial setup, check the current status each time you return to Home rather than assuming the previous connection is still active. A network change, updated server details, or subscription refresh can change the conditions for your next test. Review “status → SERVER → Global Routing → Connectivity Test” in order to identify what to check next with just a few steps.
Before connecting
- Status
- Home → Not Connected or the current connection status
- Target
- The selected server under Home → SERVER
- Routing
- The current mode under Home → Global Routing
Confirm what you’re testing before interpreting the results.
On-demand connection check
- Trigger
- Settings → On Demand
- Purpose
- Connect when configured conditions are met
- Check
- Whether the current network meets the configured conditions
With On Demand, distinguish manual actions from condition-based triggers.
If you’ve enabled Settings → On Demand, also check whether the current network meets your configured trigger conditions. Tapping the Home switch manually and connecting automatically based on conditions are two different situations. If the connection status changes, first confirm whether the conditions were met before deciding what to adjust. If you’re new to the app and haven’t learned how to connect manually, check authorization, the server, and routing first. Then set up on-demand connections; it’ll be easier to troubleshoot.
This guide explains the interface sections and the order of initial checks; it doesn’t replace the field descriptions shown in the app. If the app interface or system prompt differs from this guide, follow the current App Store product page, your device’s system prompts, and the text shown in the app. For addresses, credentials, and subscription details supplied by a service provider, refer to the information you have from that provider.
Continue checking the App Store listing and setup steps
To verify the App Store product page, developer, or device compatibility, start with our official listing verification guide. If you’ve installed the app and are ready to configure it, follow the tutorial step by step.
Verify the App Store listing View the tutorial