iOS / iPadOS · Official App Store version

Shadowrocket User Guide

This guide follows the workflow shown in the app: first verify the official App Store listing, then add the user’s existing server information or subscription to the iPhone or iPad client, and finally use Global Routing rules before testing the connection.

  • One-time purchase: $2.99
  • Global Routing
  • On Demand
  • Shadowsocks · VMess · VLESS

Device information

iOS · iPadOS APP STORE ONE-TIME PURCHASE GLOBAL ROUTING ON DEMAND ICLOUD SYNC
In-app feature guide

Six entry points from import to rule-based routing

The items below use the English names shown in the Shadowrocket interface. Select a capability on the left to see what it does, where to find it, and what to verify during setup.

Global Routing

Choose Config, Proxy, or Direct

Global Routing determines how device traffic is handled after the connection is enabled. Config matches traffic line by line against the current configuration, which suits setups that distinguish domains, IP ranges, and final policies; Proxy sends traffic through the current server; Direct keeps the connection direct. When using a rules file, first confirm that Config is selected, then check that rules run from specific conditions through FINAL so broad rules do not intercept later conditions.

Global RoutingConfig
DOMAIN-SUFFIX,example.comPROXY
GEOIP,CNDIRECT
FINALPROXY
Device and App Store access

View purchase and first-launch steps by device

The only official way to get Shadowrocket is through the App Store. Check the current product page for system requirements, price, and compatibility; before purchasing, verify the developer name and app ID.

On the App Store Download Shadowrocket

Whether a purchase can be shared across devices, which system versions can install the app, and the compatibility range are all determined by the current App Store listing.

First connection sequence

Three steps after importing configuration information

Import first, choose how traffic should be handled, then enable the connection and test it. This order separates parameter, rule, and system authorization checks.

  1. 01
    Add Server · Subscribe

    Add an existing server or subscription

    If you have details for a single server, open Add Server, choose the protocol, then enter SERVER, the port, authentication details, and transport fields exactly as provided. If you have a subscription URL, add it through Subscribe, save it, update it, and check that the expected entry appears. When importing with Scan QR Code or the clipboard, open the entry and verify the protocol and key parameters rather than relying on its name alone.

    Any mismatch in the server address, port, or authentication fields can cause later tests to fail. When multiple records are present, start with one server whose details are clear and complete the first connection before handling sorting, grouping, or duplicates. This makes it easier to determine whether a problem comes from the parameters or from how the entries are managed.

  2. 02
    Global Routing · Config

    Select a server and choose the traffic mode

    Return to Home, select the server you want to use, and confirm that it is the active selection. Then review Global Routing: when using a rules file, choose Config so DOMAIN-SUFFIX, GEOIP, IP-CIDR, and FINAL rules determine the policy in order; for a temporary check of whether all traffic can be handled by the current server, choose Proxy when appropriate; use Direct when traffic should remain direct.

    In Config mode, pay particular attention to policy names. If a rule ends with PROXY, DIRECT, or another policy, that policy must exist in the current configuration. When rules come from different configuration sources, do not mix policy groups that share a name but have different meanings. Understand where each policy actually points before changing the order.

  3. 03
    Home · Connectivity Test

    Enable the main switch and verify the result

    Turn on the connection switch in Home. The first time, the system may ask for permission to add a VPN configuration; this authorization is required to establish a system-level network connection. After granting permission, check the connection status and run Connectivity Test. If the test fails, check the device network, server address, port, protocol, authentication details, transport settings, and system time in that order. Do not change several parameters at once.

    Even after a successful test, confirm that the actual rules select the expected policies. Start with a few clear DOMAIN-SUFFIX rules, then gradually add broader GEOIP or FINAL rules. This prevents rule-order problems from being mistaken for server connection problems and makes the corresponding connection records easier to review in Data.

Official listing and purchase facts

Four sets of details to check before and after purchase

The App Store listing, purchase history, and in-app configuration address different questions. Confirm the product identity first, understand what the purchase covers, and then manage the user’s own server information.

01

Verify the developer and app ID

The App Store product page should list the product as Shadowrocket and the developer as Shadow Launch Technology Limited. The app ID is 932747118; the product URL also identifies it with id932747118. Verify the name, developer, official icon, and app ID together rather than relying only on a search-result title or the icon’s appearance.

The app icon shown on this site is provided as a recognition aid, but the App Store product page remains the final source for purchase information. Search-result order can vary by account storefront and device state, so opening the fixed product page and checking the developer and app ID is the clearest verification method.

02

Understand the price and one-time purchase

Shadowrocket is a paid commercial app. The US product page lists it at approximately $2.99 as a one-time purchase; other storefronts display local currencies, and the current page determines the actual price and availability. A one-time purchase describes how the app is bought; it does not include network routes, server accounts, or ongoing service.

Before purchasing, confirm that the current Apple ID storefront displays the product and check the amount shown at checkout. The account region affects the storefront, currency, and visibility; it does not replace the server parameters required in the app.

03

Distinguish purchase restoration from configuration backup

When changing devices or getting the app again, look for Shadowrocket in the App Store purchase history. Whether it can be restored directly depends on the current Apple ID’s purchase history and the storefront status. Restoring the app purchase restores usage rights only; it does not restore in-app servers, subscription URLs, rule files, or custom settings.

Configurations must be managed separately. Before migrating to another device, organize Config, server entries, and subscription sources within the app’s available features, and confirm what is saved in iCloud or Import from Cloud JSON. After restoring, check each item and do not delete the configuration on the original device before confirming that the data is complete.

04

Use the App Store listing and current in-app interface as references

Shadowrocket is a closed-source commercial app. Use the App Store page for product information and the current in-app interface for operation names. System requirements should always be stated as “check the App Store listing,” because compatibility information may change on the storefront page. This site avoids describing the interface with fixed version numbers, so locations that may change are not presented as permanent facts.

If the order of entries differs slightly on your device, look for the same English interface terms, such as Home, Config, Settings, Subscribe, Add Server, Global Routing, On Demand, and Connectivity Test. Feature names are more reliable long-term navigation cues than a specific screen position.

Selected FAQs

Commonly confusing steps for first-time users

Why can’t I connect after purchasing?

Completing the purchase grants the right to use the client. A connection still requires the user’s existing server information or subscription, correctly imported through Add Server or Subscribe. You must then select a server, choose a Global Routing mode, and allow the system VPN configuration.

View connection troubleshooting →

What should I check first when a Subscribe update fails?

First confirm that the device’s current network can reach the subscription URL, then check that the URL is complete and its authentication details are still valid. Do not immediately delete every server entry; keeping the original records helps determine whether the problem is with the update entry point or the existing server parameters.

View the subscription troubleshooting sequence →

How do I choose between Config, Proxy, and Direct?

Config routes traffic according to the configuration rules, Proxy sends traffic through the current server, and Direct keeps the connection direct. When using custom rules, check the rule order, policy names, and FINAL, then choose Config for verification.

View the Global Routing tutorial →

Does a successful test mean all rules are correct?

Connectivity Test mainly checks the connection path; by itself, it cannot prove that every rule selected the expected policy. Also review the Config contents, rule order, and connection records in Data.

View rule troubleshooting →
Download Shadowrocket