What “Clash Verge Rev subscription setup” actually involves
Installing Clash Verge Rev is only the beginning. The application provides the control panel, Mihomo-compatible routing engine, profile management, proxy groups, and connection logs, but it does not automatically include servers or internet access. To make the client useful, you normally need to add a valid subscription, download its profile, choose an active proxy group, and enable the system proxy or TUN mode that matches your use case.
That is why searches such as Clash Verge Rev subscription setup, how to add a Clash subscription, and Clash Verge Rev proxy nodes not working usually come from the same point in the workflow: the app is installed, but the user is unsure which screen to open next. A profile may have been imported without being selected, a subscription may have expired, or a node group may still be set to an unavailable provider. The interface can look ready even when no traffic is using the intended route.
This guide follows the everyday workflow rather than assuming advanced YAML knowledge. You will check the subscription before importing it, add the URL in the correct place, update the profile safely, inspect proxy groups, select a node, enable routing, and verify the result with connections and external checks. Menu names can vary slightly between Clash Verge Rev releases, operating systems, and Mihomo builds, but the underlying sequence remains the same.
Use only a subscription or configuration that you are authorized to use. A subscription URL may contain a private token, so treat it like a password: do not publish it in screenshots, paste it into a public issue, or send it to an untrusted support account. If the provider gives you a short import link, keep the original link somewhere secure in case the local profile needs to be reinstalled.
Prepare the subscription and verify the client
Before opening the profile page, identify what your provider actually gave you. A subscription may be presented as a URL ending in a token, a one-click import link, a QR code, or a static configuration file such as .yaml or .yml. These formats are related but not identical. A subscription URL is normally designed to be refreshed later, while a downloaded YAML file is only a snapshot unless you manually replace it.
Check the following items before importing:
- Compatibility: confirm that the provider supports Clash, Mihomo, Clash Meta, or another format accepted by your client. A Shadowrocket-only or WireGuard-only profile may not work in Clash Verge Rev.
- Validity: look at the subscription expiry date, device limit, traffic allowance, and any restrictions on simultaneous connections.
- Privacy: keep the complete URL private. If you need to report an error, redact the domain path, token, and identifying query parameters.
- Network access: make sure the computer can reach the subscription host before enabling Clash. If the URL is blocked or returns an HTML login page, the client cannot build a usable profile.
- Node availability: confirm whether the plan includes actual proxy nodes rather than only a rules template or an empty base configuration.
Now open Clash Verge Rev and let it finish loading. If the application displays a pending update, install it only when the package source is trustworthy and the release matches your operating system. Close competing VPN or proxy clients while testing. Two applications can both claim to control the system proxy, rewrite the same port, or install separate tunnel components, making a correct subscription appear broken.
On the main window, locate the profile or configuration area. You should be able to distinguish between a profile that has been imported, a profile that is currently selected, and a profile that has been updated successfully. These are three different states. Seeing a file in the list does not prove that Clash Verge Rev is using it, and seeing a recent update time does not prove that the profile contains reachable nodes.
Add a subscription URL to Clash Verge Rev
Open the Profiles or Subscriptions section, depending on the version of Clash Verge Rev installed on your computer. Look for an input field or button such as New, Add, Import, or Import from URL. The correct option is the one intended for a remote profile address, not the file picker used for a local YAML file.
Paste the complete subscription URL into the address field. Avoid adding spaces before or after the address, and do not replace characters that appear unusual in the token. Some URLs contain encoded symbols, question marks, ampersands, or long strings of letters and numbers. A browser may wrap the address visually, but it must remain one continuous URL when pasted into the client.
Give the profile a recognizable name if the application asks for one. A name such as Home subscription, Work profile, or Provider A monthly is more useful than leaving several profiles labeled with similar timestamps. Do not put the secret token into the visible name. A clear label helps you identify the correct configuration later without exposing private access information in screenshots.
Confirm the import action and wait for the download to finish. The first import may take longer because Clash Verge Rev must retrieve the remote document, parse proxy definitions, build groups, and process rules. Do not repeatedly click the import button during this stage. Multiple copies of the same subscription can make the profile list confusing and may create the impression that updates are failing.
A successful import commonly produces a profile card or row with a name, update time, and status indicator. Open the profile details if available and check whether it contains proxy groups or nodes. If the profile is listed but shows zero proxies, an empty group, or a parsing error, the problem is usually upstream of node selection. It may be the wrong format, an expired subscription, a provider-side outage, or a profile that requires a converter service before Clash can read it.
Do not assume that a browser opening the subscription URL means the import is valid. Some providers return a web dashboard, an authentication page, or a usage message when the token is missing. Clash needs a configuration response in a supported format. If the response is visibly HTML rather than YAML or a compatible encoded profile, ask the provider for the correct Clash or Mihomo subscription endpoint.
Update the profile without losing track of changes
Subscriptions are designed to be updated. Providers may rotate server addresses, remove overloaded nodes, change rule groups, or renew traffic metadata. In the profile list, find the refresh, update, or circular-arrow control associated with the imported subscription. Select the intended profile first if several entries are present, then start one update and wait for the status message to complete.
An update normally replaces or regenerates the local configuration from the remote source. It does not necessarily preserve manual edits made directly inside the downloaded profile. This distinction matters: if you hand-edit a YAML file and later refresh the subscription, the provider’s version may overwrite those changes. For durable customizations, use the client’s supported Overrides or patch mechanism when available, and keep a backup of important settings.
After an update, check more than the timestamp. Confirm that:
- the profile still appears as enabled or selectable;
- proxy groups contain members instead of showing an empty list;
- the primary group has a reasonable default selection;
- rules and rule providers loaded without parse errors;
- the profile does not unexpectedly switch to a different mode or port.
If the update fails, read the exact error rather than immediately replacing the URL. A timeout suggests that the subscription host could not be reached. An HTTP 401 or 403 response often points to an expired token, account restriction, or invalid authorization. A successful HTTP response followed by a parser error may indicate that the provider returned an unsupported format. These cases require different fixes, and repeatedly changing nodes will not repair a subscription download that never completed.
When a provider offers several links, label them clearly and test one at a time. Avoid importing every regional or device-specific link into the same profile list unless you genuinely need them. A smaller list is easier to audit, update, and troubleshoot. If you cancel a subscription, remove its local profile and any saved private URL from shared computers so that another person cannot accidentally continue using it.
Understand proxy groups and select a usable node
After the profile is loaded, open the Proxies or Proxy page. You will often see a hierarchy rather than one flat list. A top-level group may contain regional groups, automatic testing groups, fallback groups, or individual nodes. The group names are created by the profile author, so labels such as Proxy, 手动切换, Auto, or Fallback can mean different things in different subscriptions.
The important concept is that selecting a node inside a child group is not always enough. Traffic may be routed through the top-level group selected by the rules. If the rules reference a group called Proxy but you only change a separate regional group that is not connected to it, normal requests may continue using the previous node. Follow the group relationship and confirm which group the active rules actually call.
| Group or option | Typical purpose | What to check |
|---|---|---|
| Manual selector | Lets you choose one node directly | Choose a node with a recent successful delay test and acceptable load |
| URL test group | Measures nodes against a test URL | Confirm the test target is reachable and the delay is not the only quality signal |
| Fallback group | Moves to another node when the current one fails | Check the fallback order and whether failed nodes are removed automatically |
| Regional group | Organizes nodes by location or provider label | Verify that the top-level proxy group actually references this group |
| DIRECT | Sends traffic without a proxy | Use it only when the profile rules intend direct access for that destination |
A low delay number is useful but not conclusive. It may measure a lightweight HTTP request while the node struggles with sustained downloads, TLS connections, UDP traffic, or streaming. Start with a node that reports a successful test, then observe real connections while opening the service you intend to use. If one node is fast for a small test but repeatedly resets long sessions, try another node or an automatic group.
Be careful with automatic selection. An automatic group may choose a node based on delay, health checks, provider-defined priorities, or a cached result. That is convenient for normal use, but it can make troubleshooting less predictable because the selected node changes while you are testing. For diagnosis, temporarily select one known node manually. Once routing is confirmed, return to an automatic or fallback group if it better fits your daily workflow.
Enable the system proxy or TUN mode
Choosing a node does not automatically route every application on your computer. Open the general settings page and find the system proxy switch. In many desktop environments, enabling this option changes the operating system’s HTTP and HTTPS proxy settings to the local Clash Verge Rev port. Browsers and applications that respect system proxy settings may begin using the selected route immediately.
System proxy mode is usually the simplest first test because it is easy to enable and disable. It is appropriate for browsers, package managers, and applications that honor the operating system proxy. However, command-line tools, games, launchers, background services, and applications with their own networking stack may ignore it. A browser working in system proxy mode does not prove that every process on the computer is routed the same way.
TUN mode works at a lower networking layer and can capture traffic from applications that do not understand ordinary HTTP proxy settings. It may be useful for software that connects directly, uses UDP, or ignores system proxy variables. TUN typically requires additional permission, a network extension, or administrator approval. Read the prompt carefully and enable only the components you understand.
Do not enable system proxy, TUN, another VPN, and manually configured application proxies all at once during the first test. Layered routing can cause loops, port conflicts, DNS confusion, and misleading logs. Use this controlled sequence:
- Select one known profile and one known node.
- Enable the system proxy and leave TUN disabled.
- Test a browser and inspect the connection list.
- If the target application still bypasses Clash, disable the system proxy if necessary and test TUN according to the application’s requirements.
- Keep only the mode that produces clear, stable results for your workflow.
Pay attention to the local port shown in settings. If another application already occupies that port, Clash may fail to start the listener or may silently fall back to a different value. When using a terminal application, environment variables such as HTTP_PROXY, HTTPS_PROXY, and their lowercase equivalents may be required, but the values must match the local port and scheme exposed by Clash Verge Rev. Do not copy a SOCKS address into a tool that expects an HTTP proxy without checking its documentation.
Verify the route with logs and repeatable checks
The most reliable verification is observable evidence. Open the Connections or Logs view and generate a request from the application you are testing. You should see the destination hostname, the selected rule, the outbound group or node, and the connection state. A row marked DIRECT is not automatically wrong; many local services should bypass the proxy. The question is whether the result matches the profile rules and your intention.
Use a simple browser test first. Open a site that displays your public IP or network region, then compare the result with the route shown in Clash. Avoid treating one IP-check page as absolute proof because websites may use cached results, different protocols, or their own location databases. The connection log is more useful for confirming that the request entered Clash and which policy handled it.
Next, test the real application. For a browser, look for multiple connections rather than a single page load: DNS requests, HTTPS sessions, image hosts, authentication endpoints, and content delivery domains may follow different rules. If only the homepage works while sign-in or media fails, inspect the additional hostnames in Connections. A rule covering one domain does not automatically cover every related service.
For a terminal tool, first check whether the process inherited the intended proxy variables. Then make a small request and observe whether a corresponding connection appears in Clash. If the command succeeds but no row appears, it may have used a cached result, a direct route, or a separate proxy setting. If the row appears as DIRECT, review rule order before changing subscriptions. Rules are evaluated in order, and a broad direct rule placed above a specific proxy rule can explain apparently inconsistent behavior.
DNS settings also deserve attention when the application shows a hostname but the connection fails before TLS. A fake-IP or redirection mode can interact differently with local networks, captive portals, antivirus software, and applications that insist on numeric address behavior. Change one DNS-related option at a time and record the result. Avoid applying a complicated configuration copied from an unrelated forum post before you know which symptom you are solving.
Common setup failures and practical fixes
The subscription will not import
Check whether the URL is complete, still active, and reachable without a second web login. If the client reports a timeout, test the subscription host through a normal browser or another permitted network. If the provider returns an access-denied response, verify the account and token rather than changing proxy nodes. If the response is not a supported Clash or Mihomo configuration, request the correct format from the provider.
The profile appears but has no usable nodes
Open the profile details and look for parser warnings, empty proxy sections, or provider-specific errors. Some providers issue a base profile that expects external proxy providers to be loaded separately. Others return an encoded format that requires a compatible converter. A successful download with no nodes is different from a network timeout, so capture the profile status and ask focused questions instead of saying only that “Clash does not work.”
A node is selected but traffic remains direct
Confirm that system proxy or TUN is enabled, then inspect a live connection. Check the active mode—Rule, Global, or Direct—because Direct mode can intentionally bypass proxy groups. In Rule mode, inspect the matching rule and group. In Global mode, use it temporarily as a diagnostic comparison, not as a permanent substitute for understanding your rules. If Global works but Rule does not, the subscription’s rule order, rule providers, or group references deserve attention.
An update changed the behavior
Compare the profile’s groups, rules, and node list before and after the update if you have a backup. Providers may rename groups or alter the default selection. Re-select the intended top-level group, remove duplicate stale profiles, and test a single node. If you rely on local overrides, verify that the override still matches the new group names; an override targeting a deleted group cannot affect the updated configuration.
The connection is slow or unstable
Test several nodes at different times and separate latency from throughput. A node near your location may have excellent ping but be overloaded, while a slightly more distant node may handle sustained traffic better. Check whether the issue affects one application or every destination. Review the connection logs for repeated retries, TLS failures, UDP errors, or frequent node switching. If all nodes fail simultaneously, investigate the subscription status, local network, DNS, and provider outage before assuming that one server is defective.
A low-maintenance daily workflow
Once the first setup works, keep the routine simple. Start Clash Verge Rev, confirm that the intended profile is active, and check that the selected group still has a usable node. You do not need to test every node each morning. A quick connection check is enough unless a service is failing or the provider has announced maintenance.
Refresh the subscription according to the provider’s guidance rather than repeatedly updating it throughout the day. Excessive updates can make it difficult to tell whether a problem came from a node, a rule change, or a temporary download failure. When you do update, note the time and test the main services you depend on.
Use a manual node while investigating a problem, then return to a fallback or automatic group after the route is stable. Keep local overrides documented, especially if they contain custom domain rules, DNS changes, or port adjustments. A short note explaining why an override exists can save time after a profile update or a computer migration.
When you finish using a network that requires direct access, such as a captive-portal Wi-Fi network, disable the system proxy if the portal cannot load. Likewise, turn off TUN or system proxy before testing an unrelated VPN. Many “random” connection failures are simply two network controllers competing for the same traffic.
A practical checklist before you consider setup complete
Clash Verge Rev is ready for everyday use when the subscription updates successfully, the active profile contains real nodes, the top-level proxy group points to the node or child group you intended, and the routing mode matches the applications you need to cover. You should also be able to explain what the Connections view shows for a successful request and why a particular local service may correctly appear as DIRECT.
- The subscription URL is private, valid, and stored somewhere safe.
- The correct profile is selected rather than merely listed.
- The profile contains proxy groups, rules, and reachable nodes.
- A known node has been selected for the first test.
- System proxy or TUN is enabled intentionally, not accidentally.
- Logs show the expected hostname, rule, and outbound group.
- The real application has been tested instead of relying only on a latency result.
- Competing VPN and proxy controls are disabled while troubleshooting.
Some lightweight proxy tools make the first click look simpler, but they can hide profile parsing errors, offer limited visibility into rule matching, or provide few ways to separate system-proxy traffic from applications that bypass it. Clash Verge Rev requires a little more attention during subscription setup, yet its profile updates, explicit proxy groups, selectable nodes, Mihomo logs, and optional TUN mode make the workflow easier to inspect and adapt. If you want a client that keeps these controls visible across common desktop scenarios, Download Clash for free and browse freely →