Clash for Android: How to Add Subscriptions and Switch Nodes

Learn the essential Clash for Android workflow without dealing with technical jargon. Follow clear on-screen steps to import your subscription, update profiles, test node speed, select a server, and choose the right proxy mode for everyday browsing.

Clash for Android: The Basic Workflow

Clash for Android becomes much easier to use once the workflow is separated into a few clear tasks: install a compatible client, import a subscription, refresh the profile when needed, test the available nodes, select a server, and enable the proxy mode that matches your needs. The names of buttons can vary between Android clients and mihomo-based interfaces, but the underlying process is usually the same.

A subscription is not the same thing as the Clash application. The application provides the interface and runs the proxy kernel; the subscription provides the profile, proxy nodes, proxy groups, DNS settings, and routing rules. If the app opens successfully but shows no profiles or proxies, that does not necessarily mean the installation failed. It usually means that a profile has not been imported yet.

Before starting, prepare the complete subscription URL supplied by your service provider. It is normally an https:// address that contains an account token. Do not replace it with the provider's ordinary website address, and do not paste a shortened version unless the provider specifically documents that format. Anyone who obtains the full URL may be able to access your profile or consume your traffic quota.

Treat the Subscription URL as Private

Do not publish the link in screenshots, chat groups, public configuration files, or issue reports. If it has been exposed, revoke or reset it from the provider's account panel and import the replacement URL in Clash for Android.

Install the Client and Approve Android Permissions

Choose an Android client that is compatible with the configuration format and protocols used by your subscription. Many current clients use the mihomo kernel, while older applications may use the discontinued original Clash kernel and lack support for newer protocols. If a provider requires Hysteria2, TUIC, Reality, WireGuard, or another newer feature, an outdated client may import the profile but fail to load some nodes.

After installation, open the client and review its first-run prompts carefully. Android commonly asks for permission to create a VPN service when you enable a system-wide tunnel. This is expected: Android does not allow an ordinary application to capture device traffic without the operating system's VPN permission. Tap the confirmation button only after checking that the request comes from the Clash client you installed.

  • VPN permission: required for VPN or TUN mode. Android normally displays a system confirmation dialog the first time the tunnel starts.
  • Notification permission: useful on recent Android versions because the client may need a persistent notification while the VPN service is active.
  • Battery usage: unrestricted or optimized battery settings can affect background updates and long-running connections. The exact menu depends on the phone manufacturer.
  • Local network access: needed only when you intentionally allow LAN access or use local services through the tunnel.

Do not enable every advanced option immediately. First confirm that the profile can be imported and that a basic proxy connection works. Features such as TUN, LAN access, IPv6 handling, and custom DNS interception change how the entire device sends traffic and are easier to troubleshoot after the basic path is working.

Add a Subscription URL

The profile import entry is usually named Profiles, Configuration, Profiles Management, or Subscriptions. Open that page and look for an add button, a plus icon, or an option such as From URL. Avoid manually creating a local profile unless you already have a complete YAML configuration; a subscription URL is the simplest way to obtain the provider's current nodes and rules.

  1. Open Clash for Android and enter the profile or configuration section.
  2. Tap the add button and choose the URL or subscription import option.
  3. Paste the complete subscription URL into the address field.
  4. Give the profile a short name, such as Primary subscription, so it is easy to identify later.
  5. Save the entry, then tap it or use the download button to fetch the profile.
  6. After the download finishes, select the new profile as the active configuration.

Some providers offer a subscription-converter page with separate links for different clients. If several formats are available, choose a Clash or mihomo-compatible format rather than a generic VPN export. A converted profile may also include customized rules and proxy groups, so do not edit it before confirming that the original version works.

Once the profile is loaded, open the proxy or groups screen. You should see one or more groups containing nodes. A group may be called Proxy, Auto, Fallback, Streaming, or something provider-specific. If the profile appears in the list but contains no proxies, check whether the URL was copied completely and whether the provider's account has an active subscription.

Import Success Has Two Parts

Seeing a profile name only proves that the file was saved. You also need to confirm that the profile was downloaded completely and that its proxy groups contain usable nodes. An empty group usually points to a failed download, an expired subscription, or an incompatible configuration format.

Update the Profile and Read Its Status

Subscription profiles change over time. Providers may add nodes, remove expired servers, change ports, or update routing rules without changing the URL. For that reason, importing the link once is not enough. Use the profile's refresh or update action whenever nodes disappear, a service announces a configuration change, or the profile's expiration information is close to its limit.

On most Android clients, the profile list shows a refresh icon or a context menu beside each URL-based profile. Tap it to download the latest content. Keep the existing profile selected while the update runs unless the client specifically asks you to switch. A temporary update failure should not be treated as proof that the old profile is invalid; network access to the provider's subscription server may simply be unavailable at that moment.

  • Updated successfully: the profile timestamp changes and the node or rule list may be different.
  • HTTP 401 or 403: the subscription token may be invalid, expired, revoked, or restricted by the provider.
  • Timeout or connection failure: the subscription server cannot be reached from the current network. Try again on another connection.
  • Parse or YAML error: the returned content may not be a Clash configuration, or the profile may use fields unsupported by the installed kernel.
  • Download succeeds but groups are empty: inspect the provider's format options and confirm that the selected client supports the required protocols.

Automatic updates are convenient, but they should not run too frequently. A reasonable interval depends on the provider, commonly once or twice a day. Excessive update requests can waste mobile data, trigger provider rate limits, or make it harder to tell whether a later problem was caused by a new profile. If the client offers an update-on-Wi-Fi option, use it for large profiles.

Test Node Speed and Choose a Server

Node testing helps compare latency, but it does not measure every aspect of real-world performance. A latency test usually sends a small request to a URL and records how quickly a response begins. It does not guarantee high download speed, stable video playback, or access to every destination. Treat the result as a screening tool, not as an absolute ranking.

  1. Open the proxy group that contains the available nodes.
  2. Tap the test, speed-test, or latency-test control. If the client asks for a test URL, use the default URL first.
  3. Wait until several nodes have results instead of judging from one measurement.
  4. Ignore nodes that show timeout, connection refused, or repeated failures.
  5. Choose a node with acceptable latency and stable test results, then tap it to make it the active member of the group.
  6. Open a normal website or application and confirm that the selected node works in actual use.

The active selection is often made at the proxy-group level rather than on the global node list. For example, selecting a server inside the Proxy group affects traffic that matches rules pointing to Proxy. Selecting a node in a different group, such as Streaming, may not change ordinary browsing at all. When switching appears to have no effect, check which group the current rules actually use.

What you see Likely meaning What to do
Low latency and pages load normally The node is a good candidate for daily use Keep it selected and observe stability
Low latency but downloads are slow The test endpoint is responsive, but bandwidth or congestion is poor Try another node and compare a real download
High latency with successful connection The node works but is geographically distant or congested Use it only when its route is specifically needed
Repeated timeout The node is unavailable, blocked, or incorrectly configured Refresh the profile and test another node
Node changes but traffic does not The wrong proxy group or mode is being used Check the active group and routing mode

For everyday browsing, stability is usually more valuable than the lowest single latency result. A node that stays connected for several hours is often a better choice than one that wins a brief speed test but disconnects during video calls or large downloads.

Choose the Right Proxy Mode

Clash for Android commonly provides several operating modes. The labels differ between clients, but the practical differences are consistent. Start with the least invasive mode that covers the applications you need, then move to a system-wide mode only when necessary.

Global Mode

Global mode sends all traffic handled by Clash through the selected proxy group or node. It is useful for testing because it removes most rule-matching uncertainty: if an application works in Global mode but not in Rule mode, the problem may be the profile's rules rather than the node itself. The drawback is that domestic services, local addresses, and bandwidth-heavy applications may also use the proxy.

Rule Mode

Rule mode follows the rules contained in the active profile. A rule may send a domain or IP range to DIRECT, a proxy group, or REJECT. This is normally the best everyday choice when the provider supplies a maintained rule set, because different traffic can use different paths automatically. If one website behaves unexpectedly, inspect its matched rule before changing nodes repeatedly.

Direct Mode

Direct mode bypasses the proxy and connects to destinations through the local network. Use it as a diagnostic option when you need to confirm that a website or application is reachable without Clash. It is not a substitute for a proxy when the destination requires a different route.

VPN or TUN Mode

Android's VPN service captures traffic from more applications than the ordinary system proxy setting. TUN-based operation can provide broader interception and is useful for applications that ignore HTTP or SOCKS proxy settings. It may also affect local-network discovery, battery usage, DNS handling, and applications that reject VPN connections. Enable it only after confirming the basic profile and node work correctly.

A useful diagnostic sequence is to test one node in Global mode, return to Rule mode, and then check the specific application. If Global works while Rule does not, review the matched rule, DNS behavior, or the selected group. If neither mode works, focus on the node, subscription, permissions, or network connection first.

A Reliable Daily Routine

Once the initial setup is complete, daily operation should require only a few checks. Open the client, confirm that the intended profile is active, verify that the VPN switch is on when system-wide coverage is needed, and look at the selected proxy group before starting a sensitive or bandwidth-heavy task. The Android notification is useful because it shows whether the service is still running, but it does not prove that every application is using the proxy.

  • Refresh the profile if the node list is empty, outdated, or full of failures.
  • Test two or three nodes instead of repeatedly reconnecting to one unstable server.
  • Use Rule mode for normal mixed traffic when the profile has suitable rules.
  • Use Global mode temporarily to distinguish routing problems from node problems.
  • Turn off LAN access unless another device genuinely needs to connect through the Android client.
  • Check Android battery restrictions if the tunnel stops after the screen has been off for a while.
  • Do not run several VPN applications at the same time; Android normally permits only one active VPN service.

If pages load but a particular application fails, check whether the app uses certificate pinning, UDP, QUIC, its own DNS resolver, or a network security policy that blocks VPN traffic. Some applications also cache DNS or connection states, so fully closing and reopening the app after switching nodes can produce a more useful test.

Do Not Change Everything at Once

When troubleshooting, change one variable at a time: first test another node, then another mode, then refresh the profile, and only afterward investigate DNS or TUN settings. Changing the profile, node, mode, and DNS configuration together makes the original cause difficult to identify.

Frequently Asked Questions

Why does my subscription import successfully but show no nodes?

The saved URL may have returned an error page instead of a Clash profile, the subscription may have expired, or the client may not support the configuration format or protocols used by the provider. Refresh the profile, check its status message, and confirm that the provider offers a Clash or mihomo-compatible link.

Why does switching a node not change my connection?

You may have switched a node inside a group that is not used by the current rules. Open the active proxy group and confirm its selected member. Also check whether the client is in Direct mode or whether the application is bypassing the Android VPN service.

Is the node with the lowest latency always the fastest?

No. Latency measures response time to the test endpoint, while actual speed depends on congestion, bandwidth, routing, and the destination service. Compare stability and real browsing performance before choosing a daily node.

Should I use Global mode or Rule mode?

Use Rule mode for ordinary daily traffic when the profile has reliable rules. Use Global mode as a temporary test or when you deliberately want all captured traffic to use the selected proxy. Direct mode is useful for checking whether a problem exists without the proxy.

Continue with the Setup

Install a compatible Clash client, import your private subscription URL, refresh it when needed, and select a stable node from the correct proxy group. For platform downloads and the broader configuration workflow, use the links below.

Download the Clash Client

Rule-based routing needs a client to take over traffic first. Head to the download hub, pick a client for your platform, then come back to this guide to finish setting up system proxy or TUN takeover.

Download Clash