Free & open source · Rule-based · Every platform

Open-source, multi-protocol
rule-based proxy client

Clash is a cross-platform proxy tool powered by a rule engine: domain, IP, region and rule sets decide whether each connection goes through your proxy or straight out. It speaks Shadowsocks, VMess, VLESS, Trojan, Hysteria2, TUIC and more, on Windows, macOS, Android, iOS and Linux.

Free, open-source clients Downloads from official releases Up and running in 5 minutes
5Platforms
10+Proxy protocols
6Actively maintained clients
GPL-3.0Open-source license
Proxy providers

No nodes yet? Pick a provider first

Clash is just the client. You need a subscription from a provider to use it. These are the Clash-compatible providers we recommend.

Er1

Ermaoyun (二猫云)

9.9/10
3-carrier optimizedIEPLUnlimited devices

From From ¥20/mo for 130 GB

Peak-hour download 210 Mbps · Packet loss 0.3%

Coupon: TIZIZHINAN20% off at checkout

Yu2

Yuzhouyun (宇宙云)

9.7/10
All IEPLNo speed capFlexible billing

From From ¥25/mo for 120 GB

Peak-hour download 195 Mbps · Packet loss 0.4%

Coupon: YUZHOU55320% off all plans at checkout

Gu3

Guangsuyun (光速云)

9.4/10
IPLCNative IPTransparent nodes

From From ¥23/mo for 148 GB

Peak-hour download 230 Mbps · Packet loss 0.2%

No coupon right now

See all provider picks and the buying guide →

Contains affiliate links; see the disclosure on the providers page.

Every platform

Pick your operating system

Every platform has an actively maintained client. Click through for our pick and the installers.

Not sure which one? Compare 14 clients side by side, or run the Mihomo core on a server.

Key features

More than a proxy: a traffic control center

Subscriptions, rules, proxy groups, DNS and TUN work together, so you always know where each connection goes.

Rule-based routing

Route by domain, IP range, GeoIP, process or rule set — direct, proxy or reject. Local services skip the detour; everything else goes through your proxy.

Subscriptions & YAML config

Beginners import a subscription URL in one click and nodes stay up to date; power users can maintain a clean, readable YAML config by hand.

One client, every protocol

SS, VMess, VLESS, Trojan, Hysteria2, TUIC, WireGuard and more in a single client — no juggling multiple tools.

Proxy groups

Manual select, latency test, failover and load balancing switch between nodes automatically to keep you connected.

Tamper-resistant DNS

fake-ip, DoH, DoT and per-domain resolvers cut down on DNS poisoning and leaks that send traffic down the wrong route.

TUN transparent proxy

A virtual network adapter captures terminals, games and desktop apps that ignore the system proxy — true system-wide proxying.

Core capability

Rules decide where every connection goes

Rules are matched top to bottom and the first hit wins. Add community-maintained rule sets and you can keep local traffic direct and route the rest through your proxy — right out of the box.

  • Match by domain, IP range, region and process
  • Manage nodes, proxy groups and rules in one YAML file
  • Rule Providers pull online rule sets and keep them updated
  • See which rule each connection hit, live in the web dashboard
  • Compatible with original Clash, Premium and Mihomo configs
rules
rule-providers:
  reject:
    type: http
    behavior: domain
    url: https://.../reject.txt
    interval: 86400

rules:
  - RULE-SET,reject,REJECT       # block ads
  - DOMAIN-SUFFIX,openai.com,US  # pin a region
  - PROCESS-NAME,git,Proxy       # match by process
  - IP-CIDR,192.168.0.0/16,DIRECT
  - GEOIP,CN,DIRECT
  - MATCH,Proxy
Protocol support

All the major proxy protocols

Based on the Mihomo core; discontinued original Clash clients support only some of these.

Shadowsocks

The classic, with UDP and plugin support

VMess

UUID auth, multiple transports and TLS

VLESS Reality

XTLS Vision, Reality and multiple transports

Trojan

TLS camouflage, with WS and gRPC

Hysteria2 QUIC

Stays fast on lossy, unstable networks

TUIC QUIC

Low latency, with UDP relay

WireGuard

Standard peer, MTU and DNS settings

AnyTLS

TLS outbound that reuses idle sessions

Snell / ShadowTLS

PSK auth and TLS obfuscation

SOCKS5

Auth, TLS and UDP relay

HTTP / HTTPS

Standard HTTP proxy outbound

SSH

Tunnel traffic over SSH

Getting started

Connected in three steps

No command line needed — it all happens in the app.

01

Download and install a client

Clash Verge Rev for Windows, macOS and Linux; FlClash for Android; Shadowrocket or Stash for iOS.

02

Import your subscription URL

Paste the subscription URL from your provider into the Subscriptions / Profiles page, update it, and check that the node list loads.

03

Pick a node and turn it on

Run a latency test and pick a node. On desktop, enable the system proxy or TUN; on mobile, allow and enable the VPN connection.

Use cases

Traffic worth routing on its own

Different tasks need different routes. Rules keep them apart.

Development

Give code hosts, package registries, container images and APIs their own rules, and stop git, npm and pip from timing out.

AI tools

Put AI assistants, model consoles and API docs in their own group, and send long-lived sessions through your most stable nodes.

Academic research

Reach research databases and journals worldwide while keeping campus and local resources direct.

Remote work

Route meetings, shared docs and internal dashboards separately — and watch for routing conflicts with your company VPN or TUN.

Cross-region access

Split exits by region or service, keep local services direct, and keep your account sign-in location consistent.

Multi-device sync

Use the same subscription and rule setup on desktop and phone. FlClash can even sync configs over WebDAV.

FAQ

Common questions about Clash

What is Clash?

Clash is a family of rule-based proxy clients and cores. It hands your device's traffic to a rule engine, which decides whether each connection goes through a proxy, goes direct, or is rejected. Clash itself provides no proxy nodes — you get those from a provider or host your own.

How is Clash different from a VPN?

A VPN usually sends all of a device's traffic through a single remote tunnel. Clash is built around rule-based routing: domain, IP, region or rule set decides where each connection goes. With TUN mode on, Clash can also capture traffic from apps that ignore the system proxy.

Is Clash free?

The desktop and Android Clash clients and the Mihomo core are all free, open-source software. Compatible iOS apps (Shadowrocket, Stash, etc.) are paid apps on App Stores outside mainland China. Proxy nodes come from third-party providers and have nothing to do with the client itself.

Is Clash still maintained?

The original Clash core and projects like Clash for Windows are discontinued. Today's mainstream clients are built on the Mihomo (formerly Clash.Meta) core — Clash Verge Rev, FlClash and Clash Party are all actively maintained.

How are Clash Meta and Mihomo related?

Clash.Meta was renamed Mihomo. It is a compatible fork of the original Clash that adds VLESS, Reality, Hysteria2, TUIC, WireGuard, rule sets, richer DNS and more.

Which client should I download?

Start with Clash Verge Rev on Windows, macOS and Linux, and FlClash on Android. On iOS, choose Shadowrocket, Stash or Quantumult X. See our client recommendations for a full comparison.

Do I need a subscription URL to use Clash?

Most users import nodes, proxy groups and rules from a subscription URL. Without one, you can write the YAML by hand or use self-hosted nodes, but that's harder for beginners.

Is Clash safe?

Safety depends on where your client, config and nodes come from. Only get clients from official GitHub Releases or the App Store, never import configs from unknown sources, don't expose external-controller to the internet, and keep your subscription URL private.

Ready? Download Clash for free

Pick your platform, download straight from the official release page, and follow the guide — you'll be set up in 5 minutes.