Before You Begin
Clash for Android is a rule-based proxy client that can route selected applications and websites through proxy nodes while leaving other traffic connected directly. Installing the application is only the first step. To use it effectively, you normally need a subscription from a proxy service provider, import that subscription into the client, download a profile, select a node, and then enable the Android VPN service.
This guide is written for beginners who have installed Clash for Android or a compatible Android client powered by a Clash-compatible core. The names of menus may differ slightly between releases, forks, and devices, but the overall workflow remains similar. In some versions, you may see Profiles, Subscriptions, or Configuration; these usually refer to the same basic profile-management area.
A subscription is not the same thing as the Clash application. Clash is the client and traffic engine, while the subscription is provided by a separate service. The subscription URL contains server information, proxy protocols, policy groups, and routing rules. Treat this URL like a password: anyone who obtains it may be able to use your service or consume your traffic allowance.
What You Will Complete
By the end of this walkthrough, you will know how to import a subscription, update its profile, test node latency, switch servers, enable proxy mode, and troubleshoot the most common connection problems.
1Check the App and Subscription Details
Before importing anything, confirm that your Android client supports the configuration format supplied by your provider. Modern subscriptions may contain YAML-based Clash profiles, while some providers offer a conversion page that can generate a profile for Clash Meta or Mihomo. If the provider lists several formats, choose the one explicitly marked for Clash, Clash Meta, or Mihomo.
You should also check whether the application is current. Older Clash for Android builds may lack support for newer protocols, modern rule syntax, or recently introduced Android background restrictions. If a provider gives you a profile URL but the app reports an unsupported proxy type, updating the client or using a compatible Mihomo-based client may be necessary.
Information to Prepare
- A working subscription URL supplied by your proxy service provider.
- The provider's account status, expiration date, and remaining traffic allowance.
- A stable Wi-Fi or mobile-data connection for the first profile download.
- Permission to create an Android VPN connection when the client requests it.
- Optional provider instructions for DNS, TUN mode, IPv6, or application-based routing.
Subscription links commonly begin with https://, although a provider may present a shortened URL or a one-click import link. Do not paste a random configuration URL from an unknown source. A malicious profile can redirect traffic, add unwanted rules, or expose your browsing metadata. Use the provider's official dashboard and copy the complete URL rather than manually retyping it.
Protect Your Subscription URL
Do not publish your subscription link in screenshots, public chats, issue reports, or social media posts. If you accidentally expose it, revoke or regenerate the link from your provider dashboard.
2Add the Subscription to Clash for Android
Open Clash for Android and go to the profile-management screen. Depending on the build, this may be labeled Profiles or Configuration. Look for a plus button, an import icon, or an option such as New Profile. The usual choices include importing from a URL, importing from local storage, scanning a QR code, or opening a subscription link from another application.
For a normal provider subscription, choose Import from URL. Paste the complete link into the URL field, give it a recognizable name such as “My Main Subscription,” and confirm the import. A clear name is useful if you later add work, travel, or backup subscriptions. Avoid names such as “Profile 1” because they make it difficult to identify the correct service when several profiles are installed.
- Open the Profiles or Configuration page.
- Tap the add button and select Import from URL.
- Paste the subscription URL without removing query parameters.
- Enter a descriptive profile name and save the entry.
- Tap the download or refresh icon to retrieve the profile.
- Wait until the profile shows a successful update status, then select it as active.
If the provider supplies a QR code, choose the QR import option and scan it with the Android camera permission requested by the client. QR codes are convenient, but verify the displayed URL before saving it. If the provider sent a file instead, use local import and select the downloaded .yaml or .yml file. A local file will not automatically receive server changes unless you replace it or update it manually.
When the Import Fails
An import error does not always mean the link is invalid. The link may have expired, reached a device limit, or require an account login before it can be downloaded. Copy the URL into a browser only if you understand that the browser may display the raw profile or download a configuration file. If the browser also fails, contact the provider and ask for a new subscription link.
Another common issue is an HTML response instead of a configuration file. This can happen when a captive portal, login page, or provider error page is returned. Clash cannot parse that page as YAML. Try switching temporarily between Wi-Fi and mobile data, then import again. Also check for spaces or line breaks accidentally copied before or after the URL.
3Update and Activate the Profile
Adding a subscription entry and downloading its contents are two separate actions. The entry stores the URL, while the downloaded profile contains the current nodes and rules. After the first import, open the profile's menu and tap Update, Refresh, or the circular-arrow icon. Wait for the process to finish before attempting to select a node.
Regular updates matter because providers often remove expired nodes, change server addresses, adjust traffic policies, or add new regional groups. A profile that worked last month may still appear in the app but contain obsolete endpoints. Updating also helps distinguish a client problem from a stale subscription: if every node suddenly fails, downloading a fresh profile is an important first test.
| Profile status | Meaning | Recommended action |
|---|---|---|
| Updated successfully | The profile was downloaded and parsed. | Select it and continue to node testing. |
| URL unavailable | The server, network, or subscription link could not be reached. | Check the network, link, account status, and expiration date. |
| Parse failed | The response is not valid for the selected Clash core. | Request a compatible Clash or Mihomo format from the provider. |
| Updated but no proxies | The file contains no usable proxy definitions or groups. | Inspect the provider format and ask for technical support. |
Once the profile is valid, tap it to make it active. Some clients use a check mark, highlighted row, or “Use” button to indicate activation. Activating a profile does not necessarily start proxying traffic; it only tells the core which configuration to load. You still need to select a mode, choose a node, and start the Android VPN service.
4Test Latency and Choose a Node
Open the Proxies screen after activating the profile. You may see individual servers, regional groups, automatic selection groups, and special entries such as DIRECT or REJECT. A group is a collection of choices controlled by the profile. For example, a group named “Proxy,” “Global,” or “Streaming” may contain several country nodes and may be referenced by the routing rules.
Tap the latency-test button, usually shown as a lightning icon, speedometer, or three-dot menu action. The client sends a test request to each node and displays a response time in milliseconds. This value is useful, but it is not a complete measurement of real-world performance. A node with a low ping can still be slow under load, have limited bandwidth, or perform poorly with video and file downloads.
- Connect to a stable Wi-Fi or mobile-data network.
- Run the latency test for the active proxy group.
- Ignore nodes marked unavailable, timed out, or with repeated errors.
- Compare several healthy nodes instead of selecting only the smallest number.
- Choose a node geographically close to your destination when speed is the priority.
- Open a normal website or run a short video test before deciding that the node is reliable.
Use the following table as a starting point rather than a strict rule:
| Latency | Typical experience | Use case |
|---|---|---|
| Below 80 ms | Very responsive when the node is not congested. | Browsing, calls, gaming, and interactive services. |
| 80–180 ms | Usually comfortable for general daily use. | Websites, messaging, downloads, and video. |
| 180–300 ms | Noticeable delay but often usable. | Browsing and services that require a specific region. |
| Over 300 ms | Slow handshakes and more visible response delay. | Only keep it as a backup if it is otherwise dependable. |
For everyday use, automatic groups may be more convenient than manually selecting a server. If the profile provides an Auto, URL-Test, or Fallback group, selecting it allows the configuration to choose an available node based on its rules. Manual selection is still useful when a website requires a particular region or when automatic switching produces inconsistent results.
5Enable Proxy Mode and Switch Servers
After selecting a node, return to the main screen and enable the connection switch. Android will display a system VPN permission dialog the first time. Approve it only after confirming that the request comes from your Clash client. A small VPN key or shield icon normally appears in the Android status bar when the tunnel is active.
Most Clash for Android builds provide several operating modes. Rule mode sends traffic according to the profile's rules and is the best general-purpose choice. Global mode sends most supported traffic through the selected proxy group and can help diagnose rule problems, but it may add latency to services that would otherwise work better through a direct connection. Direct mode bypasses the proxy and is useful for confirming whether a problem is caused by Clash or by the network itself.
Pro Tip: Change the Group, Not the Profile
When you only want to switch countries or servers, open the proxy group and select another node. Re-importing the subscription is unnecessary and may reset your current profile settings.
To switch nodes during normal use, open the Proxies page, select the active policy group, and tap another healthy server. The change normally applies within a few seconds. Existing connections may remain attached to the old node until they reconnect, so refresh the affected application or close and reopen its connection if the new route does not appear immediately.
After switching, test the result with more than one destination. Check a regular website, a service that needs the selected region, and an application that uses background synchronization. If only one application fails, the issue may be its own DNS cache, battery restriction, or proxy compatibility rather than the selected node.
Per-App Routing
Many Android clients include an App Management or Application Rules section. This feature lets you include or exclude individual applications from the VPN tunnel. For example, you may proxy a browser while keeping banking, local payment, or smart-home applications on a direct connection. The exact behavior varies: “selected apps” may mean only listed apps are proxied, while “excluded apps” may mean every app except the listed ones is proxied.
Read the label carefully before saving. Android may also show a system-level “VPN lockdown” option. Lockdown prevents traffic from leaving outside the VPN, which can reduce accidental leaks but may block connectivity when Clash is stopped. Enable it only when you understand the recovery process and have a reliable way to disable the setting.
6Improve Stability for Daily Use
A connection that works for five minutes can still fail during everyday background use. Android aggressively limits background activity to preserve battery, and some manufacturers apply even stronger task-killing policies. If Clash disconnects when the screen turns off, open the Android app settings and set battery usage to Unrestricted or disable battery optimization for the client. The wording differs between Android versions and manufacturers.
Allow notifications if the client uses a persistent notification to keep its service active. Do not swipe the application away from the recent-apps screen if your phone's system treats that action as a force-stop. On devices with automatic startup controls, permit Clash to start automatically after reboot if you expect the proxy to be available throughout the day.
DNS behavior is another important factor. If the profile already includes DNS settings, avoid adding random public DNS servers without understanding the consequences. Changing DNS can affect speed, domain resolution, and rule matching. When troubleshooting, keep the configuration simple: use the provider's recommended settings, disable experimental options temporarily, and test one change at a time.
- Keep the core and client updated when the provider announces compatibility changes.
- Use Rule mode for normal mixed traffic and Global mode only for testing or special requirements.
- Prefer a stable node over a node with the lowest one-time latency result.
- Update the subscription after a provider-side outage or large node replacement.
- Turn off the VPN before changing networks if Android becomes stuck during handover.
- Review the active profile whenever behavior changes after an automatic update.
Remember that a proxy does not make every connection anonymous or automatically safe. HTTPS protects the content of properly secured web sessions, but the proxy service may still observe connection metadata. Avoid entering sensitive credentials on untrusted websites, and use only providers you are legally permitted to access. Follow the laws, workplace policies, and service terms that apply to your location and network.
7Troubleshoot Common Problems
The VPN switch is on, but nothing loads: First check whether a valid node is selected rather than DIRECT or an unavailable entry. Switch to another node, then try Direct mode briefly. If Direct mode also fails, the underlying network may be offline. If Direct mode works but proxy mode does not, update the profile and test a different server.
The subscription updates but all nodes time out: Confirm that the subscription has not expired and that your provider has not changed the required core. Some providers publish separate profiles for older Clash builds and Mihomo-based clients. If the profile contains a protocol unsupported by your app, the nodes may appear in the list but fail during connection.
Only one app cannot connect: Check application routing, excluded-app settings, and whether that app uses its own VPN or DNS feature. Android applications that establish a second VPN may conflict with Clash because Android normally permits only one active VPN service. Disable the other VPN or security tunnel before testing again.
Websites open slowly after enabling Clash: Run a latency test and compare a nearby node with a distant node. Then check whether Global mode is forcing local services through a remote server. Rule mode is usually more efficient. If the issue occurs only on mobile data, test the same profile on Wi-Fi because carrier NAT, IPv6, or data-saving features may affect the result.
The connection stops when the screen turns off: Remove battery restrictions, allow background activity, and keep the persistent notification enabled. Some phone manufacturers provide a separate auto-start permission that must also be enabled. Restart the client after changing these settings.
Reset Only as a Last Resort
Clearing app data can remove profiles, permissions, logs, and custom settings. Export or copy your subscription details first, then reset the client only after simpler tests have failed.
Frequently Asked Questions
Do I need a subscription to use Clash for Android?
No. The client can load a local configuration containing your own proxy definitions, but most beginners obtain nodes through a subscription service. Clash itself does not provide servers, bandwidth, or regional access.
How often should I update my subscription?
Update it whenever the provider changes nodes, after an outage, or when several servers stop working at the same time. If your provider recommends a schedule, follow that guidance. Frequent manual updates are not necessary when the profile is stable.
Should I use the fastest node shown by the latency test?
Not automatically. Latency measures response time to the test endpoint, not sustained bandwidth, congestion, or compatibility with every service. Choose a node that combines acceptable latency, stable connections, and the region you need. Automatic groups can be useful when conditions change often.
Why does switching a node not immediately change an open connection?
Existing TCP, UDP, or WebSocket sessions may continue using the previous route until they reconnect. Refresh the application, reopen the website, or wait for the session to expire. New connections should use the newly selected node once the group change has been applied.
Clash for Android becomes much easier to manage once you separate the workflow into four ideas: the subscription supplies configuration data, the profile stores that data, the proxy group determines the selected node, and the Android VPN switch applies the routing to device traffic. Start with Rule mode, test a few reliable nodes, keep the app exempt from battery restrictions, and change one setting at a time when troubleshooting.