Skip to content

Getting started ​

Clash does not include servers or routes. Bring a Clash / mihomo configuration you choose and trust, then add it, choose a route, and connect.

Profiles may contain credentials

Treat configuration files, Profile URLs, and backups as sensitive. When asking for help publicly, never post real URLs, usernames, passwords, keys, or unredacted logs.

Connect in three steps ​

1. Add a Profile ​

Open Profiles and choose Add Profile. iPhone, iPad, and Mac can start from a Profile URL, configuration file, pasted content, or a blank Profile; iPhone and iPad can also scan a QR code. Apple TV uses an HTTP or HTTPS Profile URL.

2. Choose a route ​

Open Proxies or Nodes, find the policy group responsible for the traffic you want to change, check latency, and select a route. Automatic groups follow the health-check behavior defined by the Profile.

3. Connect ​

Return to Home and connect. The first time, approve the system request to add a VPN configuration. Rule is the recommended everyday mode: the active Profile decides whether each connection goes direct, uses a proxy, or is rejected.

Do I need a separate TUN mode?

Clash uses Apple NE Packet Tunnel; there is no extra desktop-style TUN mode to enable after connecting. In the current NE mode, tun.enable: false does not switch to a proxy-port-only mode. See NE, TUN fields, and version scope.

Need a configuration starting point?

Start with the configuration best practices and minimal template. When you need a specific field or platform difference, continue to the complete configuration reference.

Connected. What next? ​

Everyday use

Go from connected to in control.

Manage Profiles, choose nodes, change outbound modes, inspect active connections, and confirm when a new setting is actually in use.

Explore everyday use →

Continue with your device ​

Keep exploring ​