Home / Notes / Layers

The App, the Subscription, and the Config Are Not One Layer

Treat Shadowrocket as a “pay once and you are online” plan, and every later misread starts there.

2026-08-15 Structure

Why these keep getting welded into one thing

Many people open Shadowrocket the first time expecting a plan panel: pay, nodes appear, flip the switch and it works. The app itself does not provide that whole chain. It only attaches exits that already exist and rules that are already written to the iOS system channel. Without an exit the screen is empty. Without rules, traffic does not know whether to enter the tunnel. Without system authorization, the switch can be on and there is still no VPN mark. Those three can break separately. On the surface they all look like “the page will not open.”

Desktop clients often bundle the app, the subscription, and the rules into one import, so people coming from a computer assume “import once and you are done.” On iPhone the three are stored separately. Home owns exits, Config owns files, Settings owns the VPN configuration. The UI looks like grouped lists; the jobs are not the same column. Weld them together in your head and you will edit all three at once, then not know which step took effect.

This site calls the app, the subscription, and the config three layers not to invent jargon, but to give you a check order. Ask which layer is still disconnected, then act. Product placement is on the home page; tap-by-tap steps are in the tutorial. Below is only how to judge.

Layer one: you only bought the client

What the App Store sold you is a client license. It parses links, stores nodes, measures latency, switches Global Routing, reads and writes config files, and asks the system for a VPN. Those abilities stay after one purchase, and updates stay in the store. It will not invent a working host after you tap “+,” and it will not add traffic or an expiry after you flip the switch.

So “I already paid, why doesn’t it work” is usually not app fraud. The second layer is not connected. SERVER on Home showing only Add Server is the normal state of this layer installed and the next layer still empty. Flipping the switch, reinstalling, or changing region will not fill an empty list.

Layer one can also fail on its own. A look-alike name, a non-store source, or a VPN later turned off in Settings all look like “the app is there but it will not connect.” Those failures should not be fixed by swapping subscriptions. For name, icon, and App ID, see Get Shadowrocket from the App Store only.

Layer two: exits come from a subscription or a typed node

Where the host is, what the port is, whether the protocol matches, whether traffic remains, and whether the link expires are decided by the provider or by your own server. The app only stores those records and connects when you select one. An empty list, a failed update, or latency that all times out: suspect this layer first.

Layer two has two attachments. A provider subscription URL goes through Subscribe in Type and can be updated later. Host, port, and password only go through Add Server. Paste a subscription URL into Host, or treat a config URL as a subscription, and you will not get usable nodes. That misread has its own note: Subscribe is not Add Server.

A list can still mean no exit. Node names are there and every latency is a timeout: the list downloaded, the far end is down. A tiny latency number and pages still fail: the speed-test address is reachable; the proxy handshake may not be. Do not take comfort from the number, and do not reinstall the app because of it. Update the subscription or change a row. If everything still fails, go back to the provider.

Layer three: the config decides which traffic uses the exit

The config does not answer “are there nodes?” It answers “does this request go direct or into the tunnel?” The default default.conf already includes split routing. A provider may also send a remote file. Changing the subscription does not require changing the config, and editing the config is not the same as changing a set of nodes. Both addresses may start with https. They do not belong on the same tab.

When Global Routing stays on Config, what actually applies is the file currently enabled. Extra nodes will not open a site if the rule sends the request to DIRECT. The other way around, if rules also send sites that should stay direct into the tunnel, it feels like “the proxy made things slower.” That is not a broken first layer, and often not a second layer out of traffic. The third layer does not match what you expected.

Why config and subscription must be read apart: A config file is not a subscription. How to use the three observation modes: What Config, Proxy, and Direct are each looking at.

The same “it will not open” points at different layers

A failure in any of the three layers can look like a page that will not open. Changing all three at once only makes judgment harder. Locate from the symptom, then act.

What you seeSuspect firstDo not do this first
Not in the store, or the icon is wrong The app layer: region, listing, a fake Download an installer
SERVER on Home shows only Add Server No subscription imported yet, or Type is wrong Edit rules or turn on Proxy
The list has nodes; every latency times out The exit itself is down Reinstall the app
VPN is up; sites that should stay direct are also slow or fail The config sent requests that should stay direct into the tunnel Keep adding nodes
The switch is on; the status bar has no VPN The system did not allow this configuration Change the subscription URL
The same site also fails on Direct The local network or the target itself is unreachable Keep tweaking Shadowrocket

The system VPN is not a fourth layer, but it is often missed

The connection is written on an iOS VPN configuration. The app requests it; the system allows it. The first time you connect, the system asks whether to add a configuration. Refuse, and the switch on Home cannot take effect by itself. Turn that row off later in Settings and you get the same result: switch on, no VPN in the status bar.

Uninstalling the app does not always delete the system configuration at once. After a reinstall, if you do not allow it again, or Settings still holds a same-named profile from another source, you also get “I installed it, but it will not connect.” That still belongs to layer one and system authorization, not an expired subscription.

On Demand in Settings can disconnect when you leave certain networks. That is not nodes vanishing. People read “it dropped overnight, so the subscription died.” Check this item first, then update the second layer.

A suggested check order

First confirm the app is the official copy and the VPN configuration is still in the system. Then confirm Home has a node you can select, and that an update is not an empty list. Only then ask whether rules sent the request to DIRECT, or into the tunnel by mistake. Touch one layer at a time. Update a subscription, change Global Routing, switch Config, and toggle VPN in the same minute, and you will not know which step took effect.

Uninstalling and reinstalling only clears local state inside the app. Whether the subscription and the config survive depends on a backup in Data, and on whether the system still keeps the VPN configuration. Reinstall is not how you repair the second layer, and it is not a business-recovery key.

Once the three layers are distinct, connect them in order in the tutorial. If you have not purchased yet, or have not matched the icon, use the download page. Do not look for an installer on another site.