Features

Shadowrocket is a network-policy client. It does not include nodes. It builds a system VPN tunnel from the configuration you import, and it decides which requests go through a proxy and which go Direct. The sections below follow the UI: what each part does, and where to find it.

Connection and system VPN

Where: first row on Home · Settings → General → VPN & Device Management

The app uses the iOS / iPadOS Network Extension. A jailbreak is not required. The first row on Home shows connection status: Not Connected when it is down, with the master switch on the right. Screenshots on this site may show the Traditional Chinese label 未連線 in the same place.

The first time you turn the switch on, the system asks to add a VPN configuration. You must allow it and confirm with Face ID or a passcode. Without that grant, the switch can move, but no tunnel is created and the status bar will not show VPN.

  • Connected means the in-app switch is on and the status bar shows VPN.
  • If the switch is on but there is no VPN icon, return to system settings and check whether the configuration is still there, or whether another VPN app is active.
  • Turning VPN off in Control Center is a disconnect. To use it again, turn the switch on in the app.

Home screenshots · Connect steps

Shadowrocket Home, not connected
Home: status row and master switch
Shadowrocket add node
Add-node form

Servers and protocols

Where: Home → Server → Add Node, or the + in the top bar

A node is the actual exit. Parameters must come from your provider. This site does not provide them. Choose a type first, then fill in server, port, password or UUID, algorithm, and the rest. Required fields cannot be empty. Remarks are only for the list. They are not used to connect.

The type list commonly includes Shadowsocks, Vmess, Trojan, Socks5, and HTTP. Follow the installed version. A wrong type usually times out; the app does not crash. Change one field, then test. Do not edit several fields at once.

  • A filled circle marks the default node. Selecting a node is not a connection. You still have to turn the home switch on.
  • If the provider gave a QR code, use Scan QR Code. If they gave JSON, you can import from iCloud or Files.
  • Fill in plugins (kcptun, v2ray-plugin, and similar) only when the provider requires them.

Add-node walkthrough

Subscribe

Where: Add Node → Type → Subscribe

If the provider gave a URL instead of a single server, choose Subscribe. Do not paste the link into the Shadowsocks Server field. After you save, you must run Update once before the home node list appears.

  • Some links open in Safari and hand off to the app, or you can add them from the clipboard.
  • Several subscriptions can coexist. If one update fails, check that URL. Do not delete every configuration.
  • Subscription fees are charged by the provider and are separate from the App Store one-time price.

Type and Subscribe walkthrough

Shadowrocket type list
Subscribe in the type list
Global Routing on Home
Home, second row: Global Routing

Global Routing

Where: Home, second row, Config on the right

This control decides how requests travel. It is not the same as “which node is connected.” The node is the exit. Routing decides which traffic enters that exit.

  • Config: split traffic by rules. Use this for daily work when you have a rule set.
  • Proxy: most requests go through the current node. Use it to compare a failure. Do not leave it as the long-term default.
  • Direct: skip the node. Use it to see whether the fault is the node or local Wi-Fi / cellular.

If only some sites fail, switch to Proxy first. If Proxy works, check rules and DNS. If Proxy also fails, change the node. After you change the mode, read the current option on Home before you judge speed.

Configuration files and rules

Where: Config tab at the bottom

The Config page manages configuration files, not the node list. default.conf is the usual default. An orange dot marks the default file. A check mark means it is in use. You can import from iCloud, upload over Wi-Fi, or add a remote configuration.

Open a file to see counts for General, Rules, Hosts, URL Rewrite, HTTPS Decryption, Filter, and more, and to add rules or mappings. Test Rule shows whether a domain goes to proxy or Direct.

  • Updating rules does not automatically change the node you selected.
  • After you edit rules, return to Home, confirm Global Routing is still Config, then test a site.
  • With nodes but no rules, you can still start on Config, or follow the mode the provider asks for.

Config-page walkthrough

Shadowrocket configuration files
Config: local and remote files
Latency test method in Settings
Settings: latency test method

Connectivity test

Where: third row on Home · Settings → Latency Test Method

The connectivity test compares a node’s round-trip time at that moment. It is not the connection switch. Green, yellow, or timeout after a run is one sample. It depends on the network then.

  • The first connection does not need the lowest latency. Use a node the provider marks as usable.
  • If everything times out: update the subscription, then change the node. Do not treat one timeout as permanently down.
  • The test method in Settings (for example TCP) changes how you measure. It does not change the path of real visits.

Data and backup

Where: Data tab at the bottom

The Data page handles backup, moving nodes, and logs. It is not the daily on/off switch.

  • iCloud: backs up settings and configuration files. Turn it on before you change devices or upgrade the system.
  • Import / export nodes: move the node list between devices. Confirm you have a backup before you delete local nodes.
  • Statistics: traffic totals. Use them to see whether Proxy was left on and a large share of requests entered the tunnel.
  • Logs: proxy and DNS records for troubleshooting. You do not need extra records beyond automatic deletion for daily use.

After you restore a backup, you must allow the system VPN configuration again.

Data-page walkthrough

Shadowrocket Data page
Data: backup, import, and export
On Demand
Settings: On Demand

Settings and On Demand

Where: Settings tab at the bottom

Most items can stay at their defaults. Language can be English, Chinese, or another supported language. It does not change connection parameters. Color only changes the UI.

On Demand is for a setup that already connects by hand, when you want fewer switch flips. After the master switch is on, VPN follows network type (Any / Wi-Fi / Cellular) or domain rules. You can disconnect on sleep so the tunnel does not stay up in the background.

  • If rules and system status disagree, trust the system VPN state.
  • The Today widget and the in-app switch control the same connection. Do not flip both.
  • Proxy / TCP / UDP are tunnel options. Do not change them unless the provider asks.

Settings notes · Settings screenshots

Advanced

Where: configuration details · Settings → Diagnostics

These features are not required for a daily connection. Leave them off or at defaults if you do not know what they do.

  • HTTPS Decryption: requires a local certificate. Use it only for device traffic you explicitly need to inspect. It increases battery use and compatibility risk. Keep it off for daily use.
  • URL Rewrite / scripts: rewrite requests from a configuration. Enable them only from a configuration you trust.
  • Diagnostics: you can turn logs on and open VPN logs, the routing table, and system proxy settings. The address field is a local log endpoint. Open it only on a network you trust. Turn logs off when you finish.
  • Hosts / local DNS mapping: pin domain resolution. Change this only when a few domains fail, after you rule out a rule problem.

Diagnostics screenshots · FAQ

Shadowrocket Diagnostics
Diagnostics: logs and routing table