QUICKSTART · ANDROID
First-time Clash Android Setup: Subscription, Mode, Connection, and Verification
For users who already have a subscription URL and are ready to connect for the first time. Follow the steps in order; the setup usually takes under 10 min. Keep unfamiliar options at their defaults—there is no need to tune core parameters during initial setup.
SETUP ROUTE
- 01 Subscription Profile URL → Profile
- 02 Rule Mode Rule → Proxy Group
- 03 VPN Permission VpnService → Connected
- 04 Network Verification Direct + Proxy
BEFORE START
Before You Start: Prepare the Client and Subscription URL
You need two things for the first setup: an installed Clash client and a subscription URL that can be updated successfully. The client reads the configuration, applies its rules, and creates the local VPN interface; the subscription URL comes from your service provider and typically contains nodes, proxy groups, rules, and DNS settings. They serve different purposes—installing the client alone will not provide usable nodes.
If the app is not installed yet, open the Android downloads section and choose a client. Launch it after installation; there is no need to change the system proxy, Private DNS, or APN first. Some clients request notification permission on first launch. This mainly controls persistent connection status and error alerts, so decide based on your device's background-management settings. When a proxy connection is actually created, Android will show a separate system-level VPN request.
Copy the subscription URL from your current subscription service's dashboard. Select the complete URL—not just the subscription name, plan number, or webpage address. It usually starts with https:// and may contain a long path and query parameters. Treat it as a configuration credential: do not paste it into public pages, screenshots, or group chats. If the provider offers several options such as “Clash,” “Universal Subscription,” and “Raw Configuration,” choose the format explicitly marked for Clash or Mihomo.
Before you begin, also confirm that Android's system time is set to sync automatically. Certificate connections, subscription updates, and some protocols depend on accurate time. A wrong date or time zone can make the client report failed downloads, timeouts for every node, or no web access after connecting. Once these checks are complete, move on to profile import instead of troubleshooting across multiple settings pages.
STEP 01 · PROFILE
Import the Subscription and Make It Active
Find the Profile Entry
After opening the client, go to the “Configuration,” “Subscription,” or Profiles page. The initial screen may show only an add button, or it may already contain a local default profile. Choose “Import from URL,” “Add Remote Profile,” or the equivalent option. Do not choose “Import from File” unless the provider specifically gave you a local YAML file.
Paste the complete subscription URL into the address field. Use a short, recognizable name such as “Daily subscription” or the provider's name. Leave the update interval at its default the first time; overly frequent updates are unnecessary and may trigger server-side rate limits. After checking the URL, choose “Save,” “Download,” or the confirmation button in the top-right corner, then wait for the client to fetch and parse the profile.
Confirm the Import Result
After a successful import, the profile list should show the name you entered and a recent update time. Open the profile or its details to view proxy groups, node entries, and rules. There is no need to inspect every node parameter; simply confirm that the list is not empty and that no messages such as “Parse failed,” “Invalid format,” or “Request timed out” appear.
If the profile has downloaded but is not active, tap it once or use its side menu to choose “Set as active.” Most clients indicate the active profile with a check mark, radio button, or “Current” label. The mode and node selections that follow apply to the active profile. If you skip this step, the proxy page may remain empty or the client may continue using an older profile.
If the subscription update fails, reopen the provider's subscription page in a browser and confirm that the URL is still valid. Then check that no spaces were copied at the beginning or end. On mobile, copying a long link from a webpage can also include explanatory text, making the URL impossible to parse. Deleting the old entry and pasting the link again is usually faster than repeatedly editing a bad URL. If the page reports a configuration syntax problem, see Profile and subscription guidance in the glossary. For complex format compatibility issues, consult the protocol and core reference to confirm that the client and profile type match.
STEP 02 · MODE
Choose Rule Mode and an Available Node
Choose Rule Mode for First Use
Once the profile is active, open “Mode,” “Proxy Mode,” or Mode on the home or settings screen. Common choices include Rule, Global, and Direct. Choose “Rule” mode for your first setup. It uses the rules in the profile to send different requests to direct or proxy groups, making it the most reliable option for everyday use and the one most consistent with the subscription's intended configuration.
“Global” mode sends most traffic through the selected proxy. It is useful for briefly checking whether rules affect a particular site, but not as the default when you are unfamiliar with the configuration. “Direct” mode bypasses the proxy and is useful for temporarily disabling split routing or comparing network behavior. Changing modes does not choose a node automatically, so after selecting Rule mode, open the proxy page and check the main proxy group.
Choose a Node in the Proxy Group
Open “Proxy” or Proxies. This page contains more than a node list—it also shows the proxy groups defined by the profile. Group names may be “Node Select,” “Proxy,” “Proxy,” or a custom name chosen by the provider. Find the group responsible for the main traffic exit, then choose a specific node or use the automatic selection policy already included in the profile.
If the client offers a latency test, run a basic test once. The result measures the response between your current network and the node; it is not the same as download speed and cannot prove that every site is accessible. If one node times out, try another in the same group. If every node times out, do not keep switching modes—return to the profile page, update the subscription, and confirm that the system time and basic network connection are working.
Some profiles also include groups such as “Auto Select,” “Failover,” and “Streaming.” For the first connection, handle only the top-level group or the main group referenced by the rules; there is no need to edit every child group. Changing all policies at random can break the provider's intended selection chain. See Rules and routing categories in the glossary for proxy groups, rule matching, and MATCH.
After choosing the mode and node, wait a few seconds and confirm that the client shows no profile reload errors. Then return to the home screen to establish the VPN connection. The profile, mode, and node are now set; the next step only handles Android system permission, so do not change the subscription again.
STEP 03 · VPN SERVICE
Start the Connection and Approve Android VPN Permission
Turn On the Client Connection
Return to the client's home screen and find the main connection switch, start button, or Start. After you tap it, the client loads the active profile and requests an Android local VPN interface. The first time you start this client, Android displays a “Connection request” dialog, usually explaining that the app wants to set up a VPN connection and may monitor network traffic.
Check that the app name in the dialog matches the Clash client you just opened, then tap “OK.” This is Android's VpnService system permission step—not a subscription login screen—and you do not need to enter an account. Each client usually requires permission only once; Android may ask again after reinstalling, clearing app data, or switching to another client.
Confirm the Connection Status
After granting permission, return to the client home screen. In a normal state, the connection switch stays on and the page shows “Running,” “Connected,” or an equivalent status. Android's status bar should also show a key-shaped or VPN icon. Some devices place the icon in the quick settings panel; as long as the system VPN page shows the current app as connected, the connection is active.
If the switch turns off immediately after you start, check the error message on the home screen or the end of the log. Common causes include no active profile, an unfinished profile parse, a port occupied by another local proxy, or another VPN app already connected. Android generally allows only one standard VPN service to control traffic, so disconnect other VPNs before starting Clash again.
Some manufacturers restrict VPN services when an app moves to the background. During the first connection, keep the client in the foreground until the next verification step is complete. Do not immediately enable battery optimization, background freezing, or automatic cleanup. Once the connection works, decide whether to allow background operation based on your device. Background persistence and battery use are later optimizations and do not affect this basic setup.
STEP 04 · VERIFY
Verify Basic Internet Access and Proxy Rules
Test the Basic Network First
Once the connection icon appears, do not judge the result by the client status alone. Keep the current profile, Rule mode, and node unchanged, then open a browser and visit an ordinary webpage that normally works without a proxy. If it loads, the Android VPN interface is active and basic DNS and direct rules are working at least partially. If even ordinary pages fail, return to the client immediately instead of changing browser settings.
When basic access fails, follow this order: turn off the Clash connection and confirm that the phone can access the internet directly over the current Wi-Fi or mobile network; turn Clash back on and update the subscription once; then switch to another node in the main proxy group and reconnect. Change only one thing at a time and test immediately. Changing the mode, DNS, node, and system network together makes the cause difficult to identify.
Then Verify the Proxy Rules
After ordinary pages work, visit a site that should be handled by the current profile's proxy rules. If it opens and loads completely, the subscription, Rule mode, proxy group, and VPN interface are working as a complete chain. If direct sites work but a specific site fails, try another node first. If it still fails, inspect which proxy group the request may match on the proxy page instead of switching to Global mode for long-term use.
To investigate the rules further, open the client's connection records or log page and refresh the target site. The records usually show the destination domain, matched rule, and proxy group used. You only need to confirm that the request entered the expected policy; there is no need to interpret every log field. See the glossary for domain matching, Fake-IP, DNS modes, and the TUN stack.
If the client shows Connected but no webpage opens, the issue is usually related to the node, DNS, profile rules, or system time. If reviewing the basic steps on this page does not restore access, read the protocol and core reference to check whether the subscription protocol is supported by the current client core. You can also follow the blog's connected but no internet troubleshooting checklist to isolate the node, DNS, mode, and system status.
DAILY USE
Everyday Use After Setup
Everyday use usually takes three actions: start the client, confirm the active profile, and turn on the connection. When your subscription service adds or removes nodes, use “Update” on the profile page to sync it—there is no need to delete and reimport it. After updating, the client may reload the proxy groups. If your previously selected node was removed, choose another available node.
Keep Rule mode for everyday use. If a particular site behaves unexpectedly, switch nodes briefly and test again; use Global mode only to compare whether the rules are involved. Switch back to Rule mode afterward so every app does not continue using the same proxy policy. When finished, turn off the client's main connection switch and confirm that the system VPN icon disappears.
Do not copy someone else's DNS, TUN, or override settings as soon as your connection works. Compatibility varies across clients, core versions, and subscription rules, so adjust parameters only around a clearly defined problem. When the connection is stable, keeping the defaults usually makes future updates easier. To understand TUN, Fake-IP, proxy groups, or protocol types, read the glossary first. For protocol selection and core compatibility, consult the protocol reference.
SETUP COMPLETE
First Connection Complete
Keep the current profile and Rule mode. The next time you start the client, confirm that the profile is valid, then turn on the VPN connection.