iOS Network Utility

Official Shadowrocket icon

Shadowrocket

A rule-based proxy client for iPhone / iPad. It runs policy. It does not sell a network. For which button to tap, go to the tutorial.

Platform
iOS / iPadOS
Get it
Paid on the App Store
License
One-time purchase
App ID
932747118
Connection
System VPN configuration
This site
No installer

Where it sits in the chain

Many people treat it as the same thing as “the network.” It is not.

Using it fully stacks three layers. Layer one is the app itself: the client you buy on the App Store. Layer two is a subscription or nodes: host, port, protocol, expiry—from a provider. Layer three is the config and rules: which requests go direct, which use the current node. Miss a layer and it all looks like “installed but unusable.”

So it is closer to a precise switch than to a carrier. You can buy, update, and back up the switch. Power still has to be wired in separately.

The app

Parse subscriptions, store nodes, measure latency, switch Global Routing, read and write configs, request a system VPN. Those stay after one purchase.

Subscription / nodes

Provided by a provider. Expiry, rate limits, or a link missing parameters show up as an empty list or a failed connect. That is not a broken app.

Rules / config

Decide how traffic is routed. The default config already includes split routing; a provider may also send a remote config. It is not the same file as the subscription.

Who it is for

For people who manage policy themselves—not a one-tap plan panel.

A fit if

You already have a subscription or self-hosted nodes, and you want rule-based routing on iOS instead of stuffing every request into one tunnel. Also a fit if you need per-app overrides, remotely updated configs, and your own latency and logs.

A poor fit if you treat it as

It is not a network vendor. Opening it will not invent nodes. Without a subscription, buying the app only finishes layer one.

Four tabs, four jobs

This is product structure, not a procedure. To follow the screen, go to the tutorial.

ModuleWhat it decidesHow it relates to another layer
Home Current node, connection switch, Global Routing, latency test Without a subscription, SERVER often shows only Add Server
Type / Add Whether this record is a subscription or a single protocol node A subscription URL goes through Subscribe; a host you type goes through Add Server
Config Which rule file to use, local or remote Stored apart from the node list; changing the subscription does not require changing the config
Data Backup, import/export, stats, logs On a new device this leaks less than copying nodes by hand
Settings Language, test method, On Demand, diagnostics Affects when it disconnects automatically; does not provide a network

Three routing modes

Global Routing is not “good / better / best.” It is three observation modes.

ConfigRoute by the current config file. Daily use should stay here.
ProxyAlmost every request uses the current node. Only for a short check of “are the rules blocking this.”
DirectEverything goes direct. Use it to ask “is the proxy itself the problem.”

What you get when you buy the app

A one-time purchase is a client license, not unlimited network access.

Included

Install and update on this device, import your own subscription and config, use rule-based routing, request a system VPN, back up, and read diagnostics.

Not included

Any node, traffic, or expiry—and region switching, shared accounts, or an IPA. The icon must be a white teal-purple line rocket, and the name must be Shadowrocket.

Next

That is the overview

To get the app, go to Download. To follow the screen, go to the tutorial. To see which layer to check first, go to FAQ.