Setting up a VPN on an iPhone with Shadowrocket is not only a matter of installing an app and tapping the connect button. A usable setup normally requires five connected steps: obtaining a compatible client, preparing a subscription URL, importing that URL into Shadowrocket, allowing iOS to create a VPN configuration, and checking whether traffic is actually using the selected server. If any one of these steps is skipped, the app may appear to contain servers while web pages still fail to load, or it may connect successfully while the selected route is not being used by the application you are testing.
This guide explains the complete iPhone setup process in a practical order. It covers where to tap in Shadowrocket, how subscription updates work, how to choose a server, what the iOS permission prompt means, and how to separate an import problem from a route or DNS problem. Menu names can differ slightly between Shadowrocket versions and iOS releases, but the workflow remains broadly the same.
Before installation: check the app, account, and subscription
Shadowrocket is a configuration-based proxy client for Apple devices. It does not provide a server list simply because the app has been installed. You need a valid subscription or a manually prepared server configuration before there is anything useful to select. The subscription normally contains server addresses, ports, protocols, names, and sometimes routing or DNS settings. Shadowrocket reads that information and presents it as selectable nodes.
First, obtain Shadowrocket through the official App Store listing available to your Apple Account region. App availability can vary by storefront, so do not download an unknown application that uses a similar name or copies the icon. If the app cannot be found in your current App Store region, changing regions may affect existing purchases, payment methods, and subscriptions. It is safer to follow Apple’s own account rules and use a legitimate distribution method rather than installing an unverified package.
Next, confirm that the subscription provider supports Shadowrocket and the protocols included in the subscription. Common proxy protocols and formats include Shadowsocks, VMess, Trojan, VLESS, Hysteria2, and WireGuard, but support is not identical across clients. Shadowrocket may import a subscription successfully while some entries remain unusable if the configuration uses a protocol, transport, or field that the current app version does not understand.
90+
Countries available
200+
Routes available
Unlimited
Online devices
Those service-level figures describe the available network, not a promise that every route is suitable for every iPhone network or application. Your selection should be based on the destination you need to access, the route’s stability, and whether the client handles the traffic correctly. A node label such as “fast” or “premium” is not a technical test result.
- ✅ Install Shadowrocket from a legitimate App Store source.
- ✅ Copy the complete subscription URL without adding spaces or quotation marks.
- ✅ Confirm that the subscription includes protocols supported by the client.
- ✅ Close other proxy or VPN applications before creating the first connection.
- ❌ Do not paste a private subscription URL into a public URL shortener.
- ❌ Do not assume that a successful import means the connection has already been tested.
Open Shadowrocket and prepare the first configuration
After installation, open Shadowrocket and review the main screen before importing anything. The app generally displays a connection switch, a current configuration or node selector, and access to settings or the configuration list. If iOS asks for permission to add VPN configurations, you can allow it when you are ready to connect. This permission is required because iOS controls network extensions through the system settings framework.
If you already use another VPN or proxy application, disconnect it first. Running multiple clients at the same time can create competing VPN profiles, a persistent system proxy, or confusing routing results. An old client may still appear disconnected while retaining a system-level configuration. If the new connection behaves strangely, open the iPhone settings and review the VPN section to see which profile is active.
Shadowrocket usually separates manually added servers from subscription-managed configurations. A manual server entry is useful when you have one complete share link, while a subscription is preferable when the provider supplies multiple routes and expects you to refresh them from one URL. Do not choose a manual protocol field merely because it sounds familiar. A subscription URL is not the same thing as a Shadowsocks share link, a WireGuard file, or a single VMess link.
Understand the difference between links and files
A subscription URL is generally entered in the subscription management area. A single-server share link is imported through the function that recognizes that specific link format. A configuration file may need to be opened through the iOS share sheet or imported from a supported storage location. These formats can look similar to a user, but the client processes them differently.
If a provider gives you a URL beginning with a web address, do not open it in Safari as your normal setup method. The browser may display encoded text, download a file, or expose the URL in history without adding anything to Shadowrocket. Copy the URL, return to the client, and use its subscription manager. If the provider gives you a QR code or a single share link instead, use the matching import option rather than forcing it into a subscription field.
Import a subscription URL in Shadowrocket
The exact button position may change between app versions, but the usual path is easy to recognize. Open Shadowrocket, tap the add button, commonly shown as a plus sign in the upper-right corner, and select the option for adding or managing a subscription. Look for wording such as Subscribe, Subscription, or Add Subscription. Do not select a protocol-specific server form unless you are importing a single server manually.
- Copy the URL. Copy the entire subscription address from the provider’s user panel. Make sure the first and last characters are included. If the URL is split across lines in a message, copy it from the original panel instead of reconstructing it by hand.
- Open the subscription area. In Shadowrocket, tap the add control and enter the subscription management screen. On some versions, the subscription list is accessible from the configuration or server management page.
- Paste the URL. Tap the URL field and paste the copied address. If there is a remark or name field, enter a short label such as “My subscription” so you can identify it later.
- Save the entry. Tap the confirmation control, which may be labeled
Save,Done, or similar. The subscription should now appear as a separate item in the list. - Refresh the subscription. Tap the item and use the update or refresh action if the app does not fetch it automatically. Wait for the server list to finish loading before selecting a node.
After a successful update, Shadowrocket should display one or more server entries beneath the subscription or in the main node list. The list may contain country names, cities, route types, protocol labels, or provider-defined names. If the list remains empty, importing the URL again repeatedly is unlikely to solve the problem. First check whether the URL is complete, whether it has expired or reached a usage limit set by the provider, and whether the iPhone currently has ordinary internet access.
Subscription credentials should be treated like account credentials. If you accidentally send the URL to someone else, remove or regenerate it through the provider’s panel if that option is available. Avoid placing it in notes that synchronize to a shared account. When support is needed, hide the token and submit only the error message, app version, and general configuration type.
Select a server and allow the iOS VPN profile
Once the subscription has been updated, return to the main Shadowrocket screen and open the node selector. Select a route appropriate for the destination you need. For example, a Japan route is relevant when the service requires a Japanese exit location, while a route in another country may be more suitable for a different regional service. Choose according to the destination and application requirements rather than selecting the first entry in the list.
Server names can include labels such as direct, relay, IEPL, BGP, CN2, or a protocol name. These labels describe route design or transport characteristics, but they do not guarantee a particular result on your mobile carrier or Wi-Fi network. IEPL may refer to a dedicated private route, while BGP and CN2 describe network path or carrier arrangements used by providers. They should be treated as clues for comparison, not as proof that one node will always be faster.
Protocol names also need to be interpreted correctly. Shadowsocks is an encrypted proxy transport. VMess, VLESS, and Trojan are commonly used with proxy cores and may depend on transport or TLS-related fields. Hysteria2 is designed around a different transport approach, while WireGuard is a VPN protocol that requires compatible configuration handling. A client may show an imported name while failing at connection time if a required field is unsupported or missing.
After selecting a node, turn on the connection switch. iOS may display a system prompt asking whether Shadowrocket can add VPN configurations or use a VPN connection. Read the prompt and allow it if you intend to connect. You may be asked for the device passcode or biometric confirmation. This is an iOS security control, not a sign that the subscription URL was entered incorrectly.
When connected, iOS normally shows a VPN indicator in the status area or Control Center, depending on the device and system version. Shadowrocket should also show an active connection state. Keep the app open briefly and check its log or connection panel for a completed handshake and traffic activity. A green switch alone is not enough if all requests immediately fail.
Verify that the iPhone is using the selected route
Verification should happen in stages. First, open Safari and load an ordinary website to confirm that basic traffic works. Then check the apparent public IP and country using a reputable IP information service. The result should match the selected exit region when the route is intended to provide regional access. Do not rely only on the node name shown in Shadowrocket; the name is configured by the provider and may not reflect the actual exit.
Next, test the application that you actually need. Sign in, load the service homepage, search for content, and open a normal page or media item. Some applications use their own networking stack, cached DNS results, or background requests, so Safari working does not prove that every application follows the same path. If an app was already open before the VPN connection, force-close it according to Apple’s normal iOS procedure and reopen it after connecting.
DNS behavior is another part of the check. A route can appear connected while DNS requests still fail, return slowly, or reveal inconsistent regional information. If Shadowrocket provides DNS or routing options, start with the provider’s documented defaults rather than changing several resolvers at random. A DNS adjustment should be made only when the symptom suggests a name-resolution problem, such as a domain failing to resolve while other websites work.
Also check whether the selected configuration uses global routing, rule-based routing, or a direct mode. Global mode sends more traffic through the selected proxy, while rule-based mode decides according to domain, IP, or geographic rules. Direct mode may intentionally bypass the proxy. If one application works and another does not, inspect the rules before concluding that the server is unavailable. A rule may send the application, an API domain, or a content delivery domain directly.
- ✅ Confirm the iOS VPN indicator and Shadowrocket connection state.
- ✅ Test a normal website, then verify the apparent exit country.
- ✅ Reopen the target app after the connection is established.
- ✅ Check whether the active routing mode is global, rule-based, or direct.
- ✅ Test the complete workflow, including login, search, and the final destination.
- ❌ Treat a successful handshake as proof that every app is using the proxy.
- ❌ Change protocol, DNS, routing mode, and server simultaneously during troubleshooting.
Refresh subscriptions and maintain the setup
A subscription is not a one-time list that should be ignored after the first import. Providers may add routes, retire servers, change parameters, or update routing rules. Open Shadowrocket’s subscription management area periodically and use its update action. If the app offers automatic update settings, choose an interval that follows the provider’s instructions and does not create unnecessary requests on mobile data.
After an update, the previously selected node may no longer exist or may have a changed name. Check the active selection before connecting, especially after reinstalling the app, restoring an iPhone backup, changing the Apple Account, or moving between Wi-Fi and cellular data. iOS may also reset or recreate network permissions after a major system change, so review the VPN profile if the switch no longer activates.
Keep separate notes about which configuration is active, but never record the full private subscription URL in a public document. If you have several subscriptions, use clear remarks and remove old entries that are no longer valid. Multiple duplicate subscriptions make the node list harder to understand and can cause you to test an outdated configuration by mistake.
When moving from Wi-Fi to cellular data, allow the connection a moment to re-establish. A route that works on one access network may behave differently on another because of carrier filtering, IPv6 handling, captive portals, or local DNS behavior. Connect to the Wi-Fi network normally first, complete any hotel, school, airport, or café sign-in page, and then enable the VPN. Otherwise, the VPN may be unable to reach the subscription server or its selected route.
Troubleshoot common Shadowrocket setup problems
The subscription cannot be imported
Check the URL character by character and confirm that the iPhone has ordinary internet access with Shadowrocket disconnected. A copied address may contain a trailing space, a line break, or only part of the original token. If the provider’s panel offers a copy button, use it. If the URL works in neither the client nor a normal network test, ask the provider whether it is active and whether the subscription format supports Shadowrocket.
The import succeeds but the server list is empty
This commonly indicates that the URL was saved but not refreshed, the response is empty, or the returned format is not understood by the current client. Refresh the subscription once, review any import log, and check whether the provider lists a Shadowrocket-specific link. Do not manually invent missing server fields. A guessed port, hostname, or protocol parameter can create a configuration that looks complete but cannot authenticate.
Shadowrocket says connected but pages do not open
Start with a different route from the same subscription, then test whether the problem affects all websites or only one service. If everything fails, disconnect and reconnect after confirming that iOS has granted VPN permission. If ordinary websites work but one service fails, inspect its regional requirements, application rules, and DNS behavior. If Safari works but a particular app does not, close and reopen that app and review whether its domains are excluded by rule-based routing.
The connection is unstable
Compare routes one at a time and note whether the problem occurs only on cellular data, only on one Wi-Fi network, or only during long transfers. A route label alone cannot identify the cause. Try the provider’s documented alternatives, keep the client version current, and avoid stacking another VPN or proxy on top of Shadowrocket. If every available route fails after a subscription refresh, provide the provider with the client name, iOS version, approximate time of the failure, selected protocol, and sanitized error text.
Once the initial setup works, future use should be simple: refresh the subscription when necessary, select a current route, connect, and perform a quick verification after changing networks. The most reliable troubleshooting method is to change one variable at a time. That approach keeps the difference between a broken URL, an unsupported protocol, an iOS permission issue, a routing-rule mismatch, and an unsuitable server clear.