After you install from the App Store, the first time you open Shadowrocket the system asks to add a VPN configuration. Choose Allow, then confirm with Face ID, Touch ID, or the device passcode. The system owns this step. It is not a login box drawn by the app. After you confirm, open Settings → General → VPN & Device Management. Shadowrocket should appear in the list.
Many people dismiss the prompt and go looking for nodes, subscriptions, or rules. The home switch can still move, but traffic never enters a tunnel. A node answers “which server.” The VPN configuration answers “whether the system lets this app take traffic.” They are independent. Finish permission first, then import a configuration.
Why the system shows this prompt
iOS does not let a normal app silently change global routing. Shadowrocket uses Network Extension and registers itself as a VPN configuration. The system brings the tunnel up on connect. The status-bar VPN label means that configuration is connected. It does not mean a given site is proxied. That still depends on Global Routing and the rules in the current conf.
So a successful grant only means “a tunnel can be created.” With no nodes, turning the switch on may build an empty tunnel or drop quickly. That is normal. Do not read “no servers yet” as a failed grant, and do not read a failed grant as “the subscription is wrong.”
What to do on first launch
Do the following. Do not change other settings at the same time:
- Confirm the app is from the App Store, the name is Shadowrocket, and the developer is Shadow Launch Technology Limited. See Install from the App Store only.
- Open the app. When “Add VPN Configuration” appears, choose Allow and finish device authentication.
- Confirm the configuration appears in system settings. If other VPN apps are installed, note which one is active.
- Return to Shadowrocket. Home can still be an empty list. Next, import a subscription or a single server. See the illustrated tutorial.
If a notification or another sheet covers the prompt, go to the Home Screen and open the app again. Do not tap Don’t Allow repeatedly before you can read the text.
If you tapped Don’t Allow
After a deny, the connection switch often still moves, but the status bar usually has no VPN icon, and browsers and apps will not use a tunnel. That is not a node timeout. The tunnel was never created. Some system versions prompt again the next time you flip the switch. Others do not. Check the system VPN list.
If Shadowrocket is missing from the list, delete the app and reinstall from the App Store, or trigger connect again in the app. Before you reinstall, confirm the purchase is still on the same Apple ID so the store does not treat it as unpaid. Deleting the app does not always remove a VPN configuration the system already wrote. If a leftover entry looks wrong, remove it in system settings first, then install.
Permission succeeded, but you still cannot connect
Check the status bar first. If there is no VPN icon, keep working on permission. Do not change nodes, DNS, or reinstall yet. If the icon is there and a site still fails, the tunnel is up. Move to the node, Global Routing, or rules. See Global Routing.
iOS usually allows only one VPN at a time. When another VPN app, a security tool, or a company client connects, Shadowrocket is disconnected and the switch may flip off. Turning VPN off in Control Center drops the current tunnel. To use it again, turn the switch on in the app. Do not rely on Control Center alone.
If it fails only on cellular or only on one Wi-Fi network, check On Demand in Settings, and whether that network blocks VPN. Schools, hotels, and offices sometimes intercept tunnels. That is unrelated to whether the app is genuine.
When a system policy blocks it
Screen Time content and privacy restrictions can block VPN. Supervised devices and school or company profiles can also forbid adding a configuration. Reinstalling, changing nodes, or clearing cache will not help. Turn the restriction off, or have an administrator change the profile.
After you change devices or upgrade the system, restoring Shadowrocket settings from iCloud or the Files app still requires a new system VPN grant. Nodes and rules in a backup do not replace system permission. Backup and restore locations are on Settings.
Checklist
- Shadowrocket is in the system VPN list, and no other app is using VPN right now.
- The VPN icon appears in the status bar after you turn the switch on, and it disappears after you disconnect.
- A server is selected on Home before you decide whether a site can open.
- Do not reinstall over and over before permission is confirmed, and do not overlay a “fix package” from outside the App Store.
The widget and the in-app switch control the same tunnel. Before permission is granted, flipping the Home Screen widget does nothing. The system still will not write a VPN configuration. After permission is granted, do not flip both places: on in the app, off in Control Center. That looks like a “broken switch.”
When Family Sharing installs the app on another device, each device must allow the VPN configuration on its own. One purchase does not write the configuration on every device. On a supervised device or a child’s account with restrictions, only an administrator may be able to finish this step.
If Shadowrocket is in the system list, the status is Not Connected, and the app still asks for permission, delete that configuration, return to the app, and turn the switch on so the system can write it again. Do not keep several same-named configurations, or you may connect the one you are not editing.
The system prompt follows the iOS language, which may differ from the app language. Use Allow / Don’t Allow in that prompt. Screenshots on this site are Traditional Chinese; the English labels are Not Connected and Add VPN Configuration.
Button names follow the installed version. Fuller steps and screenshots are in the illustrated tutorial. Purchase and region issues are on Download and in the FAQ. This page covers system permission. It does not provide nodes or non–App Store packages.