Illustrated tutorial

The screenshots below are from the App Store product page and show the real Shadowrocket UI. They come from the Hong Kong storefront and use Traditional Chinese. On English iOS the labels are Not Connected, Global Routing, Server, and so on. The layout is the same—match by position.

01Setup

Get it only from the App Store. App ID 932747118. Developer: Shadow Launch Technology Limited.

Buy it on the App Store

  1. Open the App Store and search for Shadowrocket.
  2. Match the icon in the photo: dark blue background, white rocket. Skip results named VPN, Pro, Plus, or other extra suffixes.
  3. Buy and install. The app is a one-time purchase with no in-app subscription.
  4. Open it from the Home Screen. An empty node list is normal. You import the configuration yourself.

If your region cannot find it, use the App Store link on this page, or an Apple ID from a region that lists the app. Do not use an IPA or an enterprise-signed package.

Shadowrocket app icon
App Store icon

02Home

The four tabs at the bottom are Home, Config, Data, and Settings. The first launch usually lands on Home.

The rows on Home

  • Scan is on the left of the top bar. + on the right is for adding.
  • The first row is connection status. When it is down, English UI shows Not Connected (screenshots may show 未連線). The master switch is on the right.
  • The second row is Global Routing. Config on the right opens Rule / Proxy / Direct and similar modes.
  • The third row is the connectivity test. It measures node latency. It is not the connection switch.
  • Under Server, tap Add Node to add a single server. A filled circle marks the default node.

The first time you turn the master switch on, the system asks to add a VPN configuration. You must tap Allow, or the switch does nothing. That system prompt is not in the App Store screenshots.

Shadowrocket Home, not connected
Figure 1 · Home (not connected)

03Add a node

On Home, tap Add Node, or tap + in the top bar. Fields must match the provider. This site does not provide nodes.

Fill in parameters by type

  1. Tap Type first and choose the protocol the provider specified (Shadowsocks is the default in the screenshot).
  2. Fill in server, port, and password. Required fields cannot be empty.
  3. Choose algorithm, obfuscation, and plugins from the provider’s notes. Do not keep sample values.
  4. Remarks are optional and only help you recognize the row.
  5. If the provider gave a QR code, use Scan QR Code on this page. If they gave a JSON file, use Import JSON from iCloud or Files.
  6. Tap Done in the top right to save. The node should appear when you return to Home.
Shadowrocket add-node form
Figure 2 · Add a node

04Subscribe and types

If the provider gave a subscription URL, choose Subscribe in the type list. Do not fill it in as a single Shadowsocks server.

Choose a type

  1. On the add-node page, tap Type to open this list.
  2. For a single node: choose Shadowsocks, Vmess, Trojan, Socks5, HTTP, or another type that matches the provider.
  3. For a subscription URL: choose Subscribe, paste the URL, and save.
  4. After you save, return to Home or Config and run Update on the subscription. Nodes appear only after that.

Protocols in the list follow the installed version. Later versions may add more. A wrong type usually times out; the app does not crash.

Shadowrocket type list, including Subscribe
Figure 3 · Types (including Subscribe)

05Configuration

The second tab at the bottom is Config. It manages configuration files and rules, not the node list itself.

Configuration files

  • You can import from iCloud, upload over Wi-Fi, or add a remote configuration.
  • Local Files includes default.conf as the usual default. An orange dot marks the default. A check mark means it is in use.
  • Open default.conf to see counts for General, Rules, Hosts, URL Rewrite, HTTPS Decryption, and more.
  • To change routing, add rules in the configuration details. Do not only change the node.
Shadowrocket configuration files
Figure 4 · Configuration files
Shadowrocket default.conf details
Figure 5 · default.conf

Open default.conf

  • The upper half is the current counts: General, Rules, Hosts, URL Rewrite, and more.
  • You can add rules, mappings, or URL rewrites.
  • Test Rule shows whether a domain goes to proxy or Direct.
  • After you edit rules, return to Home, confirm Global Routing still points to Config, then test connectivity.

06Connect

Order: have a node → allow VPN → turn the home switch on → status becomes Connected → verify with a site you normally use.

Connect from Home

  1. Select a row under Server. A filled circle marks the default node.
  2. Turn on the switch on the right of the first row. The first time, allow adding a VPN configuration.
  3. Status changes from Not Connected to Connected, and the system status bar shows VPN.
  4. To change the mode, tap Config to the right of Global Routing and switch among Rule / Proxy / Direct. Daily use is Rule (Config).
  5. For latency, use the connectivity test. Do not treat the test as a connection.

The App Store does not provide a screenshot of Connected with a node list. Use the state on your device after the switch is on.

Shadowrocket home switch location
Figure 6 · Turn the switch on from Home

07Data

The third tab at the bottom. Use it to back up, import or export nodes, and view statistics and logs.

Backup and moving nodes

  • iCloud: backs up settings and configuration files. Turn it on before you change devices.
  • You can import / export nodes, or delete local nodes. Confirm you have a backup before you delete.
  • Statistics shows traffic. Proxy / DNS logs are for troubleshooting. You do not need extra records beyond automatic deletion for daily use.
Shadowrocket Data page
Figure 7 · Data

08Settings

The fourth tab at the bottom. Most items can stay at their defaults. Change one item at a time.

Settings home

  • Language: switch among English, Chinese, and other supported languages. Screenshots on this page are Traditional Chinese; find the same rows by position.
  • Latency test method: TCP by default. Change it only if the numbers look wrong. Do not change it while you also mash the connectivity test.
  • On Demand: turns VPN on or off by network or domain. See the next screenshot.
  • Proxy / TCP / UDP: tunnel options. Do not change them unless the provider asks.
  • Diagnostics: turn logs on only while troubleshooting. Keep them off for daily use to save battery.
Shadowrocket Settings page
Figure 8 · Settings
Shadowrocket On Demand
Figure 9 · On Demand

On Demand

  • VPN follows the rules automatically only after the master switch is on.
  • You can limit the network type (for example Any / Wi-Fi / Cellular).
  • You can disconnect on sleep so the tunnel does not stay up in the background.
  • You can add domains below. Matching domains apply the matching rule.

Diagnostics

  • Enable logging only when you need to see why a disconnect happened.
  • VPN logs, the routing table, and system proxy settings are for comparing system state.
  • The address field is a local log endpoint. Open it only on a network you trust.
  • Turn logs off when you finish, so the app does not keep writing to disk.
Shadowrocket Diagnostics page
Figure 10 · Diagnostics

Screenshot source: Apple App Store product page (app ID 932747118). Copyright belongs to the developer. This page is only for matching the how-to notes. The App Store does not provide the system VPN permission prompt or a Connected view with a node list. Features follow the version installed on the device.